docker.yaml 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260
  1. ---
  2. name: Build Docker images
  3. on:
  4. pull_request:
  5. branches:
  6. - main
  7. paths-ignore:
  8. - 'docs/**'
  9. push:
  10. branches:
  11. - main
  12. tags:
  13. - v*.*.*
  14. workflow_dispatch:
  15. inputs:
  16. version:
  17. description: 'FrankenPHP version'
  18. required: false
  19. type: string
  20. schedule:
  21. - cron: '0 4 * * *'
  22. env:
  23. IMAGE_NAME: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && 'dunglas/frankenphp' || 'dunglas/frankenphp-dev' }}
  24. LATEST: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && '0' || '1' }}
  25. jobs:
  26. prepare:
  27. runs-on: ubuntu-latest
  28. outputs:
  29. # Push if it's a scheduled job, a tag, or if we're committing to the main branch
  30. push: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main' && github.event_name != 'pull_request')) && true || false }}
  31. variants: ${{ steps.matrix.outputs.variants }}
  32. platforms: ${{ steps.matrix.outputs.platforms }}
  33. metadata: ${{ steps.matrix.outputs.metadata }}
  34. php_version: ${{ steps.check.outputs.php_version }}
  35. php82_version: ${{ steps.check.outputs.php82_version }}
  36. php83_version: ${{ steps.check.outputs.php83_version }}
  37. skip: ${{ steps.check.outputs.skip }}
  38. ref: ${{ steps.check.outputs.ref || (github.event_name == 'workflow_dispatch' && inputs.version) || '' }}
  39. steps:
  40. -
  41. name: Check PHP versions
  42. id: check
  43. env:
  44. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  45. run: |
  46. PHP_82_LATEST=$(skopeo inspect docker://docker.io/library/php:8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  47. PHP_83_LATEST=$(skopeo inspect docker://docker.io/library/php:8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  48. {
  49. echo php_version="${PHP_83_LATEST},${PHP_82_LATEST}"
  50. echo php82_version="${PHP_82_LATEST//./-}"
  51. echo php83_version="${PHP_83_LATEST//./-}"
  52. } >> "${GITHUB_OUTPUT}"
  53. # Check if the Docker images must be rebuilt
  54. if [[ "${GITHUB_EVENT_NAME}" != "schedule" ]]; then
  55. echo skip=false >> "${GITHUB_OUTPUT}"
  56. exit 0
  57. fi
  58. FRANKENPHP_82_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  59. FRANKENPHP_83_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  60. if [[ "${FRANKENPHP_82_LATEST}" == "${PHP_82_LATEST}" ]] && [[ "${FRANKENPHP_83_LATEST}" == "${PHP_83_LATEST}" ]]; then
  61. echo skip=true >> "${GITHUB_OUTPUT}"
  62. exit 0
  63. fi
  64. {
  65. echo ref="$(gh release view --repo dunglas/frankenphp --json tagName --jq '.tagName')"
  66. echo skip=false
  67. } >> "${GITHUB_OUTPUT}"
  68. -
  69. uses: actions/checkout@v4
  70. if: ${{ !fromJson(steps.check.outputs.skip) }}
  71. with:
  72. ref: ${{ steps.check.outputs.ref }}
  73. -
  74. name: Set up Docker Buildx
  75. uses: docker/setup-buildx-action@v3
  76. with:
  77. version: latest
  78. -
  79. name: Create variants matrix
  80. if: ${{ !fromJson(steps.check.outputs.skip) }}
  81. id: matrix
  82. run: |
  83. METADATA="$(docker buildx bake --print | jq -c)"
  84. {
  85. echo metadata="${METADATA}"
  86. echo variants="$(jq -c '.group.default.targets|map(sub("runner-|builder-"; ""))|unique' <<< "${METADATA}")"
  87. echo platforms="$(jq -c 'first(.target[]) | .platforms' <<< "${METADATA}")"
  88. } >> "${GITHUB_OUTPUT}"
  89. env:
  90. SHA: ${{ github.sha }}
  91. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || steps.check.outputs.ref || github.sha }}
  92. PHP_VERSION: ${{ steps.check.outputs.php_version }}
  93. build:
  94. runs-on: ubuntu-latest
  95. needs:
  96. - prepare
  97. if: ${{ !fromJson(needs.prepare.outputs.skip) }}
  98. strategy:
  99. fail-fast: false
  100. matrix:
  101. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  102. platform: ${{ fromJson(needs.prepare.outputs.platforms) }}
  103. include:
  104. -
  105. race: ""
  106. qemu: true
  107. -
  108. platform: linux/amd64
  109. qemu: false
  110. race: "-race" # The Go race detector is only supported on amd64
  111. -
  112. platform: linux/386
  113. qemu: false
  114. exclude:
  115. # arm/v6 is only available for Alpine: https://github.com/docker-library/golang/issues/502
  116. -
  117. variant: php-${{ needs.prepare.outputs.php82_version }}-bookworm
  118. platform: linux/arm/v6
  119. -
  120. variant: php-${{ needs.prepare.outputs.php83_version }}-bookworm
  121. platform: linux/arm/v6
  122. steps:
  123. -
  124. uses: actions/checkout@v4
  125. with:
  126. ref: ${{ needs.prepare.outputs.ref }}
  127. -
  128. name: Set up QEMU
  129. if: matrix.qemu
  130. uses: docker/setup-qemu-action@v3
  131. with:
  132. platforms: ${{ matrix.platform }}
  133. -
  134. name: Set up Docker Buildx
  135. uses: docker/setup-buildx-action@v3
  136. with:
  137. platforms: ${{ matrix.platform }}
  138. version: latest
  139. -
  140. name: Login to DockerHub
  141. if: fromJson(needs.prepare.outputs.push)
  142. uses: docker/login-action@v3
  143. with:
  144. username: ${{ secrets.REGISTRY_USERNAME }}
  145. password: ${{ secrets.REGISTRY_PASSWORD }}
  146. -
  147. name: Build
  148. id: build
  149. uses: docker/bake-action@v4
  150. with:
  151. pull: true
  152. load: ${{ !fromJson(needs.prepare.outputs.push) }}
  153. targets: |
  154. builder-${{ matrix.variant }}
  155. runner-${{ matrix.variant }}
  156. # Remove tags to prevent "can't push tagged ref [...] by digest" error
  157. set: |
  158. *.tags=
  159. *.platform=${{ matrix.platform }}
  160. *.cache-from=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }}
  161. *.cache-from=type=gha,scope=refs/heads/main-${{ matrix.platform }}
  162. *.cache-to=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }},ignore-error=true
  163. ${{ fromJson(needs.prepare.outputs.push) && format('*.output=type=image,name={0},push-by-digest=true,name-canonical=true,push=true', env.IMAGE_NAME) || '' }}
  164. env:
  165. SHA: ${{ github.sha }}
  166. VERSION: ${{ github.ref_type == 'tag' && github.ref_name || needs.prepare.outputs.ref || github.sha }}
  167. PHP_VERSION: ${{ needs.prepare.outputs.php_version }}
  168. -
  169. # Workaround for https://github.com/actions/runner/pull/2477#issuecomment-1501003600
  170. name: Export metadata
  171. if: fromJson(needs.prepare.outputs.push)
  172. run: |
  173. mkdir -p /tmp/metadata/builder /tmp/metadata/runner
  174. builderDigest=$(jq -r '."builder-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  175. touch "/tmp/metadata/builder/${builderDigest#sha256:}"
  176. runnerDigest=$(jq -r '."runner-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  177. touch "/tmp/metadata/runner/${runnerDigest#sha256:}"
  178. env:
  179. METADATA: ${{ steps.build.outputs.metadata }}
  180. -
  181. name: Upload builder metadata
  182. if: fromJson(needs.prepare.outputs.push)
  183. uses: actions/upload-artifact@v3
  184. with:
  185. name: metadata-builder-${{ matrix.variant }}
  186. path: /tmp/metadata/builder/*
  187. if-no-files-found: error
  188. retention-days: 1
  189. -
  190. name: Upload runner metadata
  191. if: fromJson(needs.prepare.outputs.push)
  192. uses: actions/upload-artifact@v3
  193. with:
  194. name: metadata-runner-${{ matrix.variant }}
  195. path: /tmp/metadata/runner/*
  196. if-no-files-found: error
  197. retention-days: 1
  198. -
  199. name: Run tests
  200. if: ${{ !matrix.qemu && !fromJson(needs.prepare.outputs.push) }}
  201. run: |
  202. docker run --platform=${{ matrix.platform }} --rm \
  203. "$(jq -r '."builder-${{ matrix.variant }}"."containerimage.config.digest"' <<< "${METADATA}")" \
  204. sh -c 'go test ${{ matrix.race }} -v ./... && cd caddy && go test ${{ matrix.race }} -v ./...'
  205. env:
  206. METADATA: ${{ steps.build.outputs.metadata }}
  207. # Adapted from https://docs.docker.com/build/ci/github-actions/multi-platform/
  208. push:
  209. runs-on: ubuntu-latest
  210. needs:
  211. - prepare
  212. - build
  213. if: fromJson(needs.prepare.outputs.push)
  214. strategy:
  215. fail-fast: false
  216. matrix:
  217. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  218. target: ['builder', 'runner']
  219. steps:
  220. -
  221. name: Download metadata
  222. uses: actions/download-artifact@v3
  223. with:
  224. name: metadata-${{ matrix.target }}-${{ matrix.variant }}
  225. path: /tmp/metadata
  226. -
  227. name: Set up Docker Buildx
  228. uses: docker/setup-buildx-action@v3
  229. with:
  230. # Temporary fix for https://github.com/docker/buildx/issues/2229
  231. version: "https://github.com/docker/buildx.git#master"
  232. -
  233. name: Login to DockerHub
  234. uses: docker/login-action@v3
  235. with:
  236. username: ${{ secrets.REGISTRY_USERNAME }}
  237. password: ${{ secrets.REGISTRY_PASSWORD }}
  238. -
  239. name: Create manifest list and push
  240. working-directory: /tmp/metadata
  241. run: |
  242. set -x
  243. # shellcheck disable=SC2046,SC2086
  244. docker buildx imagetools create $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | map("-t " + .) | join(" ")' <<< ${METADATA}) \
  245. $(printf "${IMAGE_NAME}@sha256:%s " *)
  246. env:
  247. METADATA: ${{ needs.prepare.outputs.metadata }}
  248. -
  249. name: Inspect image
  250. run: |
  251. # shellcheck disable=SC2046,SC2086
  252. docker buildx imagetools inspect $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | first' <<< ${METADATA})
  253. env:
  254. METADATA: ${{ needs.prepare.outputs.metadata }}