build / Build and push image (push) Failing after 36s
The v1.0.1 tag claimed this work but did not contain it: the edits were still in the working copy when main was moved and pushed. This is that change. The run against v1.0.1 reached the registry and failed with 'unauthorized'. The automatic token cannot write packages without the job asking for it, so the job now requests packages: write and nothing wider. actions/checkout is pinned to a commit rather than a tag, at v4.4.0 rather than the current v7.0.1, which declares node24 that act_runner does not provide. regctl is pinned to a release instead of tracking latest. Every expansion moves into env so nothing interpolates into a shell body. Clean under actionlint and zizmor --persona=auditor. .shush.toml preserves the comments those linters require, which the comment hook was otherwise removing.
85 lines
2.2 KiB
YAML
85 lines
2.2 KiB
YAML
name: build
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
tags: ['v*']
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: build-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
REGISTRY: git.mroberts.dev
|
|
IMAGE: git.mroberts.dev/mroberts/claude-sbx
|
|
REGCTL_VERSION: v0.11.5
|
|
|
|
jobs:
|
|
build:
|
|
name: Build and push image
|
|
runs-on: linux
|
|
|
|
permissions:
|
|
contents: read
|
|
packages: write # regctl pushes the image to the registry (zizmor)
|
|
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install regctl
|
|
run: |
|
|
mkdir -p "$HOME/.local/bin"
|
|
curl -fsSL -o "$HOME/.local/bin/regctl" \
|
|
"https://github.com/regclient/regclient/releases/download/${REGCTL_VERSION}/regctl-linux-amd64"
|
|
chmod +x "$HOME/.local/bin/regctl"
|
|
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
|
|
|
|
- name: Resolve tag
|
|
id: tag
|
|
env:
|
|
REF: ${{ github.ref }}
|
|
run: |
|
|
if [[ "$REF" == refs/tags/* ]]; then
|
|
printf 'value=%s\n' "${REF#refs/tags/}" >>"$GITHUB_OUTPUT"
|
|
else
|
|
printf 'value=edge\n' >>"$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Build
|
|
env:
|
|
TAG: ${{ steps.tag.outputs.value }}
|
|
run: docker build -t "$IMAGE:$TAG" .
|
|
|
|
- name: Export image
|
|
env:
|
|
TAG: ${{ steps.tag.outputs.value }}
|
|
run: docker save "$IMAGE:$TAG" -o image.tar
|
|
|
|
- name: Push
|
|
env:
|
|
TAG: ${{ steps.tag.outputs.value }}
|
|
REGISTRY_USER: ${{ github.actor }}
|
|
# zizmor: ignore[secrets-outside-env]
|
|
REGISTRY_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
printf '%s' "$REGISTRY_TOKEN" |
|
|
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin
|
|
|
|
regctl registry set "$REGISTRY" \
|
|
--blob-chunk 50000000 \
|
|
--blob-max 50000000
|
|
|
|
regctl image import "$IMAGE:$TAG" image.tar
|
|
|
|
- name: Verify
|
|
env:
|
|
TAG: ${{ steps.tag.outputs.value }}
|
|
run: |
|
|
regctl manifest get "$IMAGE:$TAG" >/dev/null
|
|
printf 'Pushed %s:%s\n' "$IMAGE" "$TAG"
|