docker.yaml 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276
  1. ---
  2. name: Build Docker images
  3. concurrency:
  4. cancel-in-progress: true
  5. group: ${{ github.workflow }}-${{ github.ref }}
  6. on:
  7. pull_request:
  8. branches:
  9. - main
  10. paths-ignore:
  11. - 'docs/**'
  12. push:
  13. branches:
  14. - main
  15. tags:
  16. - v*.*.*
  17. workflow_dispatch:
  18. inputs:
  19. #checkov:skip=CKV_GHA_7
  20. version:
  21. description: 'FrankenPHP version'
  22. required: false
  23. type: string
  24. schedule:
  25. - cron: '0 4 * * *'
  26. permissions:
  27. contents: read
  28. env:
  29. IMAGE_NAME: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && 'dunglas/frankenphp' || 'dunglas/frankenphp-dev' }}
  30. jobs:
  31. prepare:
  32. runs-on: ubuntu-latest
  33. outputs:
  34. # Push if it's a scheduled job, a tag, or if we're committing to the main branch
  35. push: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main' && github.event_name != 'pull_request')) && true || false }}
  36. variants: ${{ steps.matrix.outputs.variants }}
  37. platforms: ${{ steps.matrix.outputs.platforms }}
  38. metadata: ${{ steps.matrix.outputs.metadata }}
  39. php_version: ${{ steps.check.outputs.php_version }}
  40. php82_version: ${{ steps.check.outputs.php82_version }}
  41. php83_version: ${{ steps.check.outputs.php83_version }}
  42. skip: ${{ steps.check.outputs.skip }}
  43. ref: ${{ steps.check.outputs.ref || (github.event_name == 'workflow_dispatch' && inputs.version) || '' }}
  44. steps:
  45. -
  46. name: Check PHP versions
  47. id: check
  48. env:
  49. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  50. run: |
  51. PHP_82_LATEST=$(skopeo inspect docker://docker.io/library/php:8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  52. PHP_83_LATEST=$(skopeo inspect docker://docker.io/library/php:8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  53. PHP_84_LATEST=$(skopeo inspect docker://docker.io/library/php:8.4 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  54. {
  55. echo php_version="${PHP_82_LATEST},${PHP_83_LATEST},${PHP_84_LATEST}"
  56. echo php82_version="${PHP_82_LATEST//./-}"
  57. echo php83_version="${PHP_83_LATEST//./-}"
  58. echo php84_version="${PHP_84_LATEST//./-}"
  59. } >> "${GITHUB_OUTPUT}"
  60. # Check if the Docker images must be rebuilt
  61. if [[ "${GITHUB_EVENT_NAME}" != "schedule" ]]; then
  62. echo skip=false >> "${GITHUB_OUTPUT}"
  63. exit 0
  64. fi
  65. FRANKENPHP_82_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:php8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  66. FRANKENPHP_83_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:php8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  67. FRANKENPHP_84_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:php8.4 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  68. if [[ "${FRANKENPHP_82_LATEST}" == "${PHP_82_LATEST}" ]] && [[ "${FRANKENPHP_83_LATEST}" == "${PHP_83_LATEST}" ]] && [[ "${FRANKENPHP_84_LATEST}" == "${PHP_84_LATEST}" ]]; then
  69. echo skip=true >> "${GITHUB_OUTPUT}"
  70. exit 0
  71. fi
  72. {
  73. echo ref="$(gh release view --repo dunglas/frankenphp --json tagName --jq '.tagName')"
  74. echo skip=false
  75. } >> "${GITHUB_OUTPUT}"
  76. -
  77. uses: actions/checkout@v4
  78. if: ${{ !fromJson(steps.check.outputs.skip) }}
  79. with:
  80. ref: ${{ steps.check.outputs.ref }}
  81. -
  82. name: Set up Docker Buildx
  83. if: ${{ !fromJson(steps.check.outputs.skip) }}
  84. uses: docker/setup-buildx-action@v3
  85. -
  86. name: Create variants matrix
  87. if: ${{ !fromJson(steps.check.outputs.skip) }}
  88. id: matrix
  89. shell: bash
  90. run: |
  91. set -e
  92. METADATA="$(docker buildx bake --print | jq -c)"
  93. {
  94. echo metadata="${METADATA}"
  95. echo variants="$(jq -c '.group.default.targets|map(sub("runner-|builder-"; ""))|unique' <<< "${METADATA}")"
  96. echo platforms="$(jq -c 'first(.target[]) | .platforms' <<< "${METADATA}")"
  97. } >> "${GITHUB_OUTPUT}"
  98. env:
  99. SHA: ${{ github.sha }}
  100. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || steps.check.outputs.ref || 'dev' }}
  101. PHP_VERSION: ${{ steps.check.outputs.php_version }}
  102. build:
  103. runs-on: ubuntu-latest
  104. needs:
  105. - prepare
  106. if: ${{ !fromJson(needs.prepare.outputs.skip) }}
  107. strategy:
  108. fail-fast: false
  109. matrix:
  110. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  111. platform: ${{ fromJson(needs.prepare.outputs.platforms) }}
  112. include:
  113. -
  114. race: ""
  115. qemu: true
  116. -
  117. platform: linux/amd64
  118. qemu: false
  119. race: "-race" # The Go race detector is only supported on amd64
  120. -
  121. platform: linux/386
  122. qemu: false
  123. exclude:
  124. # arm/v6 is only available for Alpine: https://github.com/docker-library/golang/issues/502
  125. -
  126. variant: php-${{ needs.prepare.outputs.php82_version }}-bookworm
  127. platform: linux/arm/v6
  128. -
  129. variant: php-${{ needs.prepare.outputs.php83_version }}-bookworm
  130. platform: linux/arm/v6
  131. steps:
  132. -
  133. name: Prepare
  134. id: prepare
  135. run: |
  136. platform=${{ matrix.platform }}
  137. echo "sanitized_platform=${platform//\//-}" >> "${GITHUB_OUTPUT}"
  138. -
  139. uses: actions/checkout@v4
  140. with:
  141. ref: ${{ needs.prepare.outputs.ref }}
  142. -
  143. name: Set up QEMU
  144. if: matrix.qemu
  145. uses: docker/setup-qemu-action@v3
  146. with:
  147. platforms: ${{ matrix.platform }}
  148. -
  149. name: Set up Docker Buildx
  150. uses: docker/setup-buildx-action@v3
  151. with:
  152. platforms: ${{ matrix.platform }}
  153. -
  154. name: Login to DockerHub
  155. if: fromJson(needs.prepare.outputs.push)
  156. uses: docker/login-action@v3
  157. with:
  158. username: ${{ secrets.REGISTRY_USERNAME }}
  159. password: ${{ secrets.REGISTRY_PASSWORD }}
  160. -
  161. name: Build
  162. id: build
  163. uses: docker/bake-action@v5
  164. with:
  165. pull: true
  166. load: ${{ !fromJson(needs.prepare.outputs.push) }}
  167. targets: |
  168. builder-${{ matrix.variant }}
  169. runner-${{ matrix.variant }}
  170. # Remove tags to prevent "can't push tagged ref [...] by digest" error
  171. set: |
  172. ${{ (github.event_name == 'pull_request') && '*.args.NO_COMPRESS=1' || '' }}
  173. *.tags=
  174. *.platform=${{ matrix.platform }}
  175. builder-${{ matrix.variant }}.cache-from=type=gha,scope=builder-${{ matrix.variant }}-${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }}
  176. builder-${{ matrix.variant }}.cache-from=type=gha,scope=refs/heads/main-builder-${{ matrix.variant }}-${{ matrix.platform }}
  177. builder-${{ matrix.variant }}.cache-to=type=gha,scope=builder-${{ matrix.variant }}-${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }},ignore-error=true
  178. runner-${{ matrix.variant }}.cache-from=type=gha,scope=runner-${{ matrix.variant }}-${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }}
  179. runner-${{ matrix.variant }}.cache-from=type=gha,scope=refs/heads/main-runner-${{ matrix.variant }}-${{ matrix.platform }}
  180. runner-${{ matrix.variant }}.cache-to=type=gha,scope=runner-${{ matrix.variant }}-${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }},ignore-error=true
  181. ${{ fromJson(needs.prepare.outputs.push) && format('*.output=type=image,name={0},push-by-digest=true,name-canonical=true,push=true', env.IMAGE_NAME) || '' }}
  182. env:
  183. SHA: ${{ github.sha }}
  184. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || needs.prepare.outputs.ref || 'dev' }}
  185. PHP_VERSION: ${{ needs.prepare.outputs.php_version }}
  186. -
  187. # Workaround for https://github.com/actions/runner/pull/2477#issuecomment-1501003600
  188. name: Export metadata
  189. if: fromJson(needs.prepare.outputs.push)
  190. run: |
  191. mkdir -p /tmp/metadata/builder /tmp/metadata/runner
  192. builderDigest=$(jq -r '."builder-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  193. touch "/tmp/metadata/builder/${builderDigest#sha256:}"
  194. runnerDigest=$(jq -r '."runner-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  195. touch "/tmp/metadata/runner/${runnerDigest#sha256:}"
  196. env:
  197. METADATA: ${{ steps.build.outputs.metadata }}
  198. -
  199. name: Upload builder metadata
  200. if: fromJson(needs.prepare.outputs.push)
  201. uses: actions/upload-artifact@v4
  202. with:
  203. name: metadata-builder-${{ matrix.variant }}-${{ steps.prepare.outputs.sanitized_platform }}
  204. path: /tmp/metadata/builder/*
  205. if-no-files-found: error
  206. retention-days: 1
  207. -
  208. name: Upload runner metadata
  209. if: fromJson(needs.prepare.outputs.push)
  210. uses: actions/upload-artifact@v4
  211. with:
  212. name: metadata-runner-${{ matrix.variant }}-${{ steps.prepare.outputs.sanitized_platform }}
  213. path: /tmp/metadata/runner/*
  214. if-no-files-found: error
  215. retention-days: 1
  216. -
  217. name: Run tests
  218. if: ${{ !matrix.qemu && !fromJson(needs.prepare.outputs.push) }}
  219. run: |
  220. docker run --platform=${{ matrix.platform }} --rm \
  221. "$(jq -r '."builder-${{ matrix.variant }}"."containerimage.config.digest"' <<< "${METADATA}")" \
  222. sh -c 'go test -tags ${{ matrix.race }} -v ./... && cd caddy && go test -tags nobadger,nomysql,nopgx ${{ matrix.race }} -v ./...'
  223. env:
  224. METADATA: ${{ steps.build.outputs.metadata }}
  225. # Adapted from https://docs.docker.com/build/ci/github-actions/multi-platform/
  226. push:
  227. runs-on: ubuntu-latest
  228. needs:
  229. - prepare
  230. - build
  231. if: fromJson(needs.prepare.outputs.push)
  232. strategy:
  233. fail-fast: false
  234. matrix:
  235. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  236. target: ['builder', 'runner']
  237. steps:
  238. -
  239. name: Download metadata
  240. uses: actions/download-artifact@v4
  241. with:
  242. pattern: metadata-${{ matrix.target }}-${{ matrix.variant }}-*
  243. path: /tmp/metadata
  244. merge-multiple: true
  245. -
  246. name: Set up Docker Buildx
  247. uses: docker/setup-buildx-action@v3
  248. -
  249. name: Login to DockerHub
  250. uses: docker/login-action@v3
  251. with:
  252. username: ${{ secrets.REGISTRY_USERNAME }}
  253. password: ${{ secrets.REGISTRY_PASSWORD }}
  254. -
  255. name: Create manifest list and push
  256. working-directory: /tmp/metadata
  257. run: |
  258. set -x
  259. # shellcheck disable=SC2046,SC2086
  260. docker buildx imagetools create $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | map("-t " + .) | join(" ")' <<< ${METADATA}) \
  261. $(printf "${IMAGE_NAME}@sha256:%s " *)
  262. env:
  263. METADATA: ${{ needs.prepare.outputs.metadata }}
  264. -
  265. name: Inspect image
  266. run: |
  267. # shellcheck disable=SC2046,SC2086
  268. docker buildx imagetools inspect $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | first' <<< ${METADATA})
  269. env:
  270. METADATA: ${{ needs.prepare.outputs.metadata }}