docker.yaml 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261
  1. ---
  2. name: Build Docker images
  3. concurrency:
  4. cancel-in-progress: true
  5. group: ${{ github.workflow }}-${{ github.ref }}
  6. on:
  7. pull_request:
  8. branches:
  9. - main
  10. paths-ignore:
  11. - 'docs/**'
  12. push:
  13. branches:
  14. - main
  15. tags:
  16. - v*.*.*
  17. workflow_dispatch:
  18. inputs:
  19. version:
  20. description: 'FrankenPHP version'
  21. required: false
  22. type: string
  23. schedule:
  24. - cron: '0 4 * * *'
  25. env:
  26. IMAGE_NAME: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && 'dunglas/frankenphp' || 'dunglas/frankenphp-dev' }}
  27. LATEST: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && '0' || '1' }}
  28. jobs:
  29. prepare:
  30. runs-on: ubuntu-latest
  31. outputs:
  32. # Push if it's a scheduled job, a tag, or if we're committing to the main branch
  33. push: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main' && github.event_name != 'pull_request')) && true || false }}
  34. variants: ${{ steps.matrix.outputs.variants }}
  35. platforms: ${{ steps.matrix.outputs.platforms }}
  36. metadata: ${{ steps.matrix.outputs.metadata }}
  37. php_version: ${{ steps.check.outputs.php_version }}
  38. php82_version: ${{ steps.check.outputs.php82_version }}
  39. php83_version: ${{ steps.check.outputs.php83_version }}
  40. skip: ${{ steps.check.outputs.skip }}
  41. ref: ${{ steps.check.outputs.ref || (github.event_name == 'workflow_dispatch' && inputs.version) || '' }}
  42. steps:
  43. -
  44. name: Check PHP versions
  45. id: check
  46. env:
  47. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  48. run: |
  49. PHP_82_LATEST=$(skopeo inspect docker://docker.io/library/php:8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  50. PHP_83_LATEST=$(skopeo inspect docker://docker.io/library/php:8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  51. {
  52. echo php_version="${PHP_83_LATEST},${PHP_82_LATEST}"
  53. echo php82_version="${PHP_82_LATEST//./-}"
  54. echo php83_version="${PHP_83_LATEST//./-}"
  55. } >> "${GITHUB_OUTPUT}"
  56. # Check if the Docker images must be rebuilt
  57. if [[ "${GITHUB_EVENT_NAME}" != "schedule" ]]; then
  58. echo skip=false >> "${GITHUB_OUTPUT}"
  59. exit 0
  60. fi
  61. FRANKENPHP_82_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  62. FRANKENPHP_83_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  63. if [[ "${FRANKENPHP_82_LATEST}" == "${PHP_82_LATEST}" ]] && [[ "${FRANKENPHP_83_LATEST}" == "${PHP_83_LATEST}" ]]; then
  64. echo skip=true >> "${GITHUB_OUTPUT}"
  65. exit 0
  66. fi
  67. {
  68. echo ref="$(gh release view --repo dunglas/frankenphp --json tagName --jq '.tagName')"
  69. echo skip=false
  70. } >> "${GITHUB_OUTPUT}"
  71. -
  72. uses: actions/checkout@v4
  73. if: ${{ !fromJson(steps.check.outputs.skip) }}
  74. with:
  75. ref: ${{ steps.check.outputs.ref }}
  76. -
  77. name: Set up Docker Buildx
  78. if: ${{ !fromJson(steps.check.outputs.skip) }}
  79. uses: docker/setup-buildx-action@v3
  80. with:
  81. version: latest
  82. -
  83. name: Create variants matrix
  84. if: ${{ !fromJson(steps.check.outputs.skip) }}
  85. id: matrix
  86. run: |
  87. METADATA="$(docker buildx bake --print | jq -c)"
  88. {
  89. echo metadata="${METADATA}"
  90. echo variants="$(jq -c '.group.default.targets|map(sub("runner-|builder-"; ""))|unique' <<< "${METADATA}")"
  91. echo platforms="$(jq -c 'first(.target[]) | .platforms' <<< "${METADATA}")"
  92. } >> "${GITHUB_OUTPUT}"
  93. env:
  94. SHA: ${{ github.sha }}
  95. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || steps.check.outputs.ref || 'dev' }}
  96. PHP_VERSION: ${{ steps.check.outputs.php_version }}
  97. build:
  98. runs-on: ubuntu-latest
  99. needs:
  100. - prepare
  101. if: ${{ !fromJson(needs.prepare.outputs.skip) }}
  102. strategy:
  103. fail-fast: false
  104. matrix:
  105. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  106. platform: ${{ fromJson(needs.prepare.outputs.platforms) }}
  107. include:
  108. -
  109. race: ""
  110. qemu: true
  111. -
  112. platform: linux/amd64
  113. qemu: false
  114. race: "-race" # The Go race detector is only supported on amd64
  115. -
  116. platform: linux/386
  117. qemu: false
  118. exclude:
  119. # arm/v6 is only available for Alpine: https://github.com/docker-library/golang/issues/502
  120. -
  121. variant: php-${{ needs.prepare.outputs.php82_version }}-bookworm
  122. platform: linux/arm/v6
  123. -
  124. variant: php-${{ needs.prepare.outputs.php83_version }}-bookworm
  125. platform: linux/arm/v6
  126. steps:
  127. -
  128. uses: actions/checkout@v4
  129. with:
  130. ref: ${{ needs.prepare.outputs.ref }}
  131. -
  132. name: Set up QEMU
  133. if: matrix.qemu
  134. uses: docker/setup-qemu-action@v3
  135. with:
  136. platforms: ${{ matrix.platform }}
  137. -
  138. name: Set up Docker Buildx
  139. uses: docker/setup-buildx-action@v3
  140. with:
  141. platforms: ${{ matrix.platform }}
  142. version: latest
  143. -
  144. name: Login to DockerHub
  145. if: fromJson(needs.prepare.outputs.push)
  146. uses: docker/login-action@v3
  147. with:
  148. username: ${{ secrets.REGISTRY_USERNAME }}
  149. password: ${{ secrets.REGISTRY_PASSWORD }}
  150. -
  151. name: Build
  152. id: build
  153. uses: docker/bake-action@v4
  154. with:
  155. pull: true
  156. load: ${{ !fromJson(needs.prepare.outputs.push) }}
  157. targets: |
  158. builder-${{ matrix.variant }}
  159. runner-${{ matrix.variant }}
  160. # Remove tags to prevent "can't push tagged ref [...] by digest" error
  161. set: |
  162. *.tags=
  163. *.platform=${{ matrix.platform }}
  164. *.cache-from=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }}
  165. *.cache-from=type=gha,scope=refs/heads/main-${{ matrix.platform }}
  166. *.cache-to=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }},ignore-error=true
  167. ${{ fromJson(needs.prepare.outputs.push) && format('*.output=type=image,name={0},push-by-digest=true,name-canonical=true,push=true', env.IMAGE_NAME) || '' }}
  168. env:
  169. SHA: ${{ github.sha }}
  170. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || needs.prepare.outputs.ref || 'dev' }}
  171. PHP_VERSION: ${{ needs.prepare.outputs.php_version }}
  172. -
  173. # Workaround for https://github.com/actions/runner/pull/2477#issuecomment-1501003600
  174. name: Export metadata
  175. if: fromJson(needs.prepare.outputs.push)
  176. run: |
  177. mkdir -p /tmp/metadata/builder /tmp/metadata/runner
  178. builderDigest=$(jq -r '."builder-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  179. touch "/tmp/metadata/builder/${builderDigest#sha256:}"
  180. runnerDigest=$(jq -r '."runner-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  181. touch "/tmp/metadata/runner/${runnerDigest#sha256:}"
  182. env:
  183. METADATA: ${{ steps.build.outputs.metadata }}
  184. -
  185. name: Upload builder metadata
  186. if: fromJson(needs.prepare.outputs.push)
  187. uses: actions/upload-artifact@v3
  188. with:
  189. name: metadata-builder-${{ matrix.variant }}
  190. path: /tmp/metadata/builder/*
  191. if-no-files-found: error
  192. retention-days: 1
  193. -
  194. name: Upload runner metadata
  195. if: fromJson(needs.prepare.outputs.push)
  196. uses: actions/upload-artifact@v3
  197. with:
  198. name: metadata-runner-${{ matrix.variant }}
  199. path: /tmp/metadata/runner/*
  200. if-no-files-found: error
  201. retention-days: 1
  202. -
  203. name: Run tests
  204. if: ${{ !matrix.qemu && !fromJson(needs.prepare.outputs.push) }}
  205. run: |
  206. docker run --platform=${{ matrix.platform }} --rm \
  207. "$(jq -r '."builder-${{ matrix.variant }}"."containerimage.config.digest"' <<< "${METADATA}")" \
  208. sh -c 'go test ${{ matrix.race }} -v ./... && cd caddy && go test ${{ matrix.race }} -v ./...'
  209. env:
  210. METADATA: ${{ steps.build.outputs.metadata }}
  211. # Adapted from https://docs.docker.com/build/ci/github-actions/multi-platform/
  212. push:
  213. runs-on: ubuntu-latest
  214. needs:
  215. - prepare
  216. - build
  217. if: fromJson(needs.prepare.outputs.push)
  218. strategy:
  219. fail-fast: false
  220. matrix:
  221. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  222. target: ['builder', 'runner']
  223. steps:
  224. -
  225. name: Download metadata
  226. uses: actions/download-artifact@v3
  227. with:
  228. name: metadata-${{ matrix.target }}-${{ matrix.variant }}
  229. path: /tmp/metadata
  230. -
  231. name: Set up Docker Buildx
  232. uses: docker/setup-buildx-action@v3
  233. -
  234. name: Login to DockerHub
  235. uses: docker/login-action@v3
  236. with:
  237. username: ${{ secrets.REGISTRY_USERNAME }}
  238. password: ${{ secrets.REGISTRY_PASSWORD }}
  239. -
  240. name: Create manifest list and push
  241. working-directory: /tmp/metadata
  242. run: |
  243. set -x
  244. # shellcheck disable=SC2046,SC2086
  245. docker buildx imagetools create $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | map("-t " + .) | join(" ")' <<< ${METADATA}) \
  246. $(printf "${IMAGE_NAME}@sha256:%s " *)
  247. env:
  248. METADATA: ${{ needs.prepare.outputs.metadata }}
  249. -
  250. name: Inspect image
  251. run: |
  252. # shellcheck disable=SC2046,SC2086
  253. docker buildx imagetools inspect $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | first' <<< ${METADATA})
  254. env:
  255. METADATA: ${{ needs.prepare.outputs.metadata }}