docker.yaml 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232
  1. ---
  2. name: Build Docker images
  3. on:
  4. pull_request:
  5. branches:
  6. - main
  7. push:
  8. branches:
  9. - main
  10. tags:
  11. - v*.*.*
  12. workflow_dispatch:
  13. inputs: {}
  14. schedule:
  15. - cron: '0 4 * * *'
  16. jobs:
  17. prepare:
  18. runs-on: ubuntu-latest
  19. outputs:
  20. # Push if it's a scheduled job, a tag, or if we're committing to the main branch
  21. push: ${{ toJson(github.event_name == 'schedule' || startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main' && github.event_name != 'pull_request')) }}
  22. variants: ${{ steps.matrix.outputs.variants }}
  23. platforms: ${{ steps.matrix.outputs.platforms }}
  24. metadata: ${{ steps.matrix.outputs.metadata }}
  25. php_version: ${{ steps.check.outputs.php_version }}
  26. skip: ${{ steps.check.outputs.skip }}
  27. ref: ${{ steps.check.outputs.ref }}
  28. steps:
  29. -
  30. name: Check PHP versions
  31. id: check
  32. run: |
  33. PHP_82_LATEST=$(skopeo inspect docker://docker.io/library/php:8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  34. PHP_83_LATEST=$(skopeo inspect docker://docker.io/library/php:8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  35. echo php_version="${PHP_83_LATEST},${PHP_82_LATEST}" >> "${GITHUB_OUTPUT}"
  36. # Check if the Docker images must be rebuilt
  37. if [[ "${GITHUB_EVENT_NAME}" != "schedule" ]]; then
  38. echo skip=false >> "${GITHUB_OUTPUT}"
  39. exit 0
  40. fi
  41. FRANKENPHP_82_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  42. FRANKENPHP_83_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  43. if [[ "${FRANKENPHP_82_LATEST}" == "${PHP_82_LATEST}" ]] && [[ "${FRANKENPHP_83_LATEST}" == "${PHP_83_LATEST}" ]]; then
  44. echo skip=true >> "${GITHUB_OUTPUT}"
  45. exit 0
  46. fi
  47. {
  48. echo ref="$(gh release view --repo dunglas/frankenphp --json tagName --jq '.tagName')"
  49. echo skip=false
  50. } >> "${GITHUB_OUTPUT}"
  51. -
  52. uses: actions/checkout@v4
  53. if: ${{ !fromJson(steps.check.outputs.skip) }}
  54. with:
  55. ref: ${{ steps.check.outputs.ref }}
  56. -
  57. name: Set up Docker Buildx
  58. uses: docker/setup-buildx-action@v3
  59. with:
  60. version: latest
  61. -
  62. name: Create variants matrix
  63. if: ${{ !fromJson(steps.check.outputs.skip) }}
  64. id: matrix
  65. run: |
  66. METADATA="$(docker buildx bake --print | jq -c)"
  67. {
  68. echo metadata="${METADATA}"
  69. echo variants="$(jq -c '.group.default.targets|map(sub("runner-|builder-"; ""))|unique' <<< "${METADATA}")"
  70. echo platforms="$(jq -c 'first(.target[]) | .platforms' <<< "${METADATA}")"
  71. } >> "${GITHUB_OUTPUT}"
  72. env:
  73. SHA: ${{ github.sha }}
  74. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || steps.check.outputs.ref || github.sha }}
  75. PHP_VERSION: ${{ steps.check.outputs.php_version }}
  76. build:
  77. runs-on: ubuntu-latest
  78. needs:
  79. - prepare
  80. if: ${{ !fromJson(needs.prepare.outputs.skip) }}
  81. strategy:
  82. fail-fast: false
  83. matrix:
  84. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  85. platform: ${{ fromJson(needs.prepare.outputs.platforms) }}
  86. include:
  87. - race: ""
  88. qemu: true
  89. - platform: linux/amd64
  90. qemu: false
  91. - platform: linux/386
  92. qemu: false
  93. steps:
  94. -
  95. uses: actions/checkout@v4
  96. with:
  97. ref: ${{ needs.prepare.outputs.ref }}
  98. -
  99. name: Set up QEMU
  100. if: matrix.qemu
  101. uses: docker/setup-qemu-action@v3
  102. with:
  103. platforms: ${{ matrix.platform }}
  104. -
  105. name: Set up Docker Buildx
  106. uses: docker/setup-buildx-action@v3
  107. with:
  108. platforms: ${{ matrix.platform }}
  109. version: latest
  110. -
  111. name: Login to DockerHub
  112. if: fromJson(needs.prepare.outputs.push)
  113. uses: docker/login-action@v3
  114. with:
  115. username: ${{ secrets.REGISTRY_USERNAME }}
  116. password: ${{ secrets.REGISTRY_PASSWORD }}
  117. -
  118. name: Build
  119. id: build
  120. uses: docker/bake-action@v4
  121. with:
  122. pull: true
  123. load: ${{ !fromJson(needs.prepare.outputs.push) }}
  124. targets: |
  125. builder-${{ matrix.variant }}
  126. runner-${{ matrix.variant }}
  127. # Remove tags to prevent "can't push tagged ref [...] by digest" error
  128. set: |
  129. *.tags=
  130. *.platform=${{ matrix.platform }}
  131. *.cache-from=type=gha,scope=${{ github.ref }}-${{ matrix.platform }}
  132. *.cache-from=type=gha,scope=refs/heads/main-${{ matrix.platform }}
  133. *.cache-to=type=gha,scope=${{ github.ref }}-${{ matrix.platform }}
  134. ${{ fromJson(needs.prepare.outputs.push) && '*.output=type=image,name=dunglas/frankenphp,push-by-digest=true,name-canonical=true,push=true' || '' }}
  135. env:
  136. SHA: ${{ github.sha }}
  137. VERSION: ${{ github.ref_type == 'tag' && github.ref_name || needs.prepare.outputs.ref || github.sha }}
  138. PHP_VERSION: ${{ needs.prepare.outputs.php_version }}
  139. -
  140. # Workaround for https://github.com/actions/runner/pull/2477#issuecomment-1501003600
  141. name: Export metadata
  142. if: fromJson(needs.prepare.outputs.push)
  143. run: |
  144. mkdir -p /tmp/metadata/builder /tmp/metadata/runner
  145. # shellcheck disable=SC2086
  146. builderDigest=$(jq -r '."builder-${{ matrix.variant }}"."containerimage.digest"' <<< ${METADATA})
  147. touch "/tmp/metadata/builder/${builderDigest#sha256:}"
  148. # shellcheck disable=SC2086
  149. runnerDigest=$(jq -r '."runner-${{ matrix.variant }}"."containerimage.digest"' <<< ${METADATA})
  150. touch "/tmp/metadata/runner/${runnerDigest#sha256:}"
  151. env:
  152. METADATA: ${{ steps.build.outputs.metadata }}
  153. -
  154. name: Upload builder metadata
  155. if: fromJson(needs.prepare.outputs.push)
  156. uses: actions/upload-artifact@v3
  157. with:
  158. name: metadata-builder-${{ matrix.variant }}
  159. path: /tmp/metadata/builder/*
  160. if-no-files-found: error
  161. retention-days: 1
  162. -
  163. name: Upload runner metadata
  164. if: fromJson(needs.prepare.outputs.push)
  165. uses: actions/upload-artifact@v3
  166. with:
  167. name: metadata-runner-${{ matrix.variant }}
  168. path: /tmp/metadata/runner/*
  169. if-no-files-found: error
  170. retention-days: 1
  171. -
  172. name: Run tests
  173. if: '!matrix.qemu'
  174. continue-on-error: ${{ fromJson(needs.prepare.outputs.push) }}
  175. run: |
  176. docker run --platform=${{ matrix.platform }} --rm \
  177. "$(jq -r '."builder-${{ matrix.variant }}"."containerimage.config.digest"' <<< "${METADATA}")" \
  178. sh -c 'CGO_CXXFLAGS=-fPIE CGO_CFLAGS=-fPIE CGO_LDFLAGS=-pie go test -buildmode=pie -v ./... && cd caddy && go test -buildmode=pie -v ./...'
  179. env:
  180. METADATA: ${{ steps.build.outputs.metadata }}
  181. # Adapted from https://docs.docker.com/build/ci/github-actions/multi-platform/
  182. push:
  183. runs-on: ubuntu-latest
  184. needs:
  185. - prepare
  186. - build
  187. if: fromJson(needs.prepare.outputs.push)
  188. strategy:
  189. fail-fast: false
  190. matrix:
  191. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  192. target: ['builder', 'runner']
  193. steps:
  194. -
  195. name: Download metadata
  196. uses: actions/download-artifact@v3
  197. with:
  198. name: metadata-${{ matrix.target }}-${{ matrix.variant }}
  199. path: /tmp/metadata
  200. -
  201. name: Set up Docker Buildx
  202. uses: docker/setup-buildx-action@v3
  203. with:
  204. version: latest
  205. -
  206. name: Login to DockerHub
  207. uses: docker/login-action@v3
  208. with:
  209. username: ${{ secrets.REGISTRY_USERNAME }}
  210. password: ${{ secrets.REGISTRY_PASSWORD }}
  211. -
  212. name: Create manifest list and push
  213. working-directory: /tmp/metadata
  214. run: |
  215. # shellcheck disable=SC2046,SC2086
  216. docker buildx imagetools create $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | map("-t " + .) | join(" ")' <<< ${METADATA}) \
  217. $(printf 'dunglas/frankenphp@sha256:%s ' *)
  218. env:
  219. METADATA: ${{ needs.prepare.outputs.metadata }}
  220. -
  221. name: Inspect image
  222. run: |
  223. # shellcheck disable=SC2046,SC2086
  224. docker buildx imagetools inspect $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | first' <<< ${METADATA})
  225. env:
  226. METADATA: ${{ needs.prepare.outputs.metadata }}