docker.yaml 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254
  1. ---
  2. name: Build Docker images
  3. on:
  4. pull_request:
  5. branches:
  6. - main
  7. push:
  8. branches:
  9. - main
  10. tags:
  11. - v*.*.*
  12. workflow_dispatch:
  13. inputs:
  14. version:
  15. description: 'FrankenPHP version'
  16. required: false
  17. type: string
  18. schedule:
  19. - cron: '0 4 * * *'
  20. env:
  21. IMAGE_NAME: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/')) && 'dunglas/frankenphp' || 'dunglas/frankenphp-dev' }}
  22. jobs:
  23. prepare:
  24. runs-on: ubuntu-latest
  25. outputs:
  26. # Push if it's a scheduled job, a tag, or if we're committing to the main branch
  27. push: ${{ (github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && inputs.version) || startsWith(github.ref, 'refs/tags/') || (github.ref == 'refs/heads/main' && github.event_name != 'pull_request')) && true || false }}
  28. variants: ${{ steps.matrix.outputs.variants }}
  29. platforms: ${{ steps.matrix.outputs.platforms }}
  30. metadata: ${{ steps.matrix.outputs.metadata }}
  31. php_version: ${{ steps.check.outputs.php_version }}
  32. php82_version: ${{ steps.check.outputs.php82_version }}
  33. php83_version: ${{ steps.check.outputs.php83_version }}
  34. skip: ${{ steps.check.outputs.skip }}
  35. ref: ${{ steps.check.outputs.ref || (github.event_name == 'workflow_dispatch' && inputs.version) || '' }}
  36. steps:
  37. -
  38. name: Check PHP versions
  39. id: check
  40. run: |
  41. PHP_82_LATEST=$(skopeo inspect docker://docker.io/library/php:8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  42. PHP_83_LATEST=$(skopeo inspect docker://docker.io/library/php:8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  43. {
  44. echo php_version="${PHP_83_LATEST},${PHP_82_LATEST}"
  45. echo php82_version="${PHP_82_LATEST//./-}"
  46. echo php83_version="${PHP_83_LATEST//./-}"
  47. } >> "${GITHUB_OUTPUT}"
  48. # Check if the Docker images must be rebuilt
  49. if [[ "${GITHUB_EVENT_NAME}" != "schedule" ]]; then
  50. echo skip=false >> "${GITHUB_OUTPUT}"
  51. exit 0
  52. fi
  53. FRANKENPHP_82_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.2 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  54. FRANKENPHP_83_LATEST=$(skopeo inspect docker://docker.io/dunglas/frankenphp:latest-php8.3 --override-os linux --override-arch amd64 | jq -r '.Env[] | select(test("^PHP_VERSION=")) | sub("^PHP_VERSION="; "")')
  55. if [[ "${FRANKENPHP_82_LATEST}" == "${PHP_82_LATEST}" ]] && [[ "${FRANKENPHP_83_LATEST}" == "${PHP_83_LATEST}" ]]; then
  56. echo skip=true >> "${GITHUB_OUTPUT}"
  57. exit 0
  58. fi
  59. {
  60. echo ref="$(gh release view --repo dunglas/frankenphp --json tagName --jq '.tagName')"
  61. echo skip=false
  62. } >> "${GITHUB_OUTPUT}"
  63. -
  64. uses: actions/checkout@v4
  65. if: ${{ !fromJson(steps.check.outputs.skip) }}
  66. with:
  67. ref: ${{ steps.check.outputs.ref }}
  68. -
  69. name: Set up Docker Buildx
  70. uses: docker/setup-buildx-action@v3
  71. with:
  72. version: latest
  73. -
  74. name: Create variants matrix
  75. if: ${{ !fromJson(steps.check.outputs.skip) }}
  76. id: matrix
  77. run: |
  78. METADATA="$(docker buildx bake --print | jq -c)"
  79. {
  80. echo metadata="${METADATA}"
  81. echo variants="$(jq -c '.group.default.targets|map(sub("runner-|builder-"; ""))|unique' <<< "${METADATA}")"
  82. echo platforms="$(jq -c 'first(.target[]) | .platforms' <<< "${METADATA}")"
  83. } >> "${GITHUB_OUTPUT}"
  84. env:
  85. SHA: ${{ github.sha }}
  86. VERSION: ${{ (github.ref_type == 'tag' && github.ref_name) || steps.check.outputs.ref || github.sha }}
  87. PHP_VERSION: ${{ steps.check.outputs.php_version }}
  88. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  89. build:
  90. runs-on: ubuntu-latest
  91. needs:
  92. - prepare
  93. if: ${{ !fromJson(needs.prepare.outputs.skip) }}
  94. strategy:
  95. fail-fast: false
  96. matrix:
  97. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  98. platform: ${{ fromJson(needs.prepare.outputs.platforms) }}
  99. include:
  100. -
  101. race: ""
  102. qemu: true
  103. -
  104. platform: linux/amd64
  105. qemu: false
  106. race: "-race" # The Go race detector is only supported on amd64
  107. -
  108. platform: linux/386
  109. qemu: false
  110. exclude:
  111. # arm/v6 is only available for Alpine: https://github.com/docker-library/golang/issues/502
  112. -
  113. variant: php-${{ needs.prepare.outputs.php82_version }}-bookworm
  114. platform: linux/arm/v6
  115. -
  116. variant: php-${{ needs.prepare.outputs.php83_version }}-bookworm
  117. platform: linux/arm/v6
  118. steps:
  119. -
  120. uses: actions/checkout@v4
  121. with:
  122. ref: ${{ needs.prepare.outputs.ref }}
  123. -
  124. name: Set up QEMU
  125. if: matrix.qemu
  126. uses: docker/setup-qemu-action@v3
  127. with:
  128. platforms: ${{ matrix.platform }}
  129. -
  130. name: Set up Docker Buildx
  131. uses: docker/setup-buildx-action@v3
  132. with:
  133. platforms: ${{ matrix.platform }}
  134. version: latest
  135. -
  136. name: Login to DockerHub
  137. if: fromJson(needs.prepare.outputs.push)
  138. uses: docker/login-action@v3
  139. with:
  140. username: ${{ secrets.REGISTRY_USERNAME }}
  141. password: ${{ secrets.REGISTRY_PASSWORD }}
  142. -
  143. name: Build
  144. id: build
  145. uses: docker/bake-action@v4
  146. with:
  147. pull: true
  148. load: ${{ !fromJson(needs.prepare.outputs.push) }}
  149. targets: |
  150. builder-${{ matrix.variant }}
  151. runner-${{ matrix.variant }}
  152. # Remove tags to prevent "can't push tagged ref [...] by digest" error
  153. set: |
  154. *.tags=
  155. *.platform=${{ matrix.platform }}
  156. *.cache-from=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }}
  157. *.cache-from=type=gha,scope=refs/heads/main-${{ matrix.platform }}
  158. *.cache-to=type=gha,scope=${{ needs.prepare.outputs.ref || github.ref }}-${{ matrix.platform }},ignore-error=true
  159. ${{ fromJson(needs.prepare.outputs.push) && '*.output=type=image,name=dunglas/frankenphp,push-by-digest=true,name-canonical=true,push=true' || '' }}
  160. env:
  161. SHA: ${{ github.sha }}
  162. VERSION: ${{ github.ref_type == 'tag' && github.ref_name || needs.prepare.outputs.ref || github.sha }}
  163. PHP_VERSION: ${{ needs.prepare.outputs.php_version }}
  164. -
  165. # Workaround for https://github.com/actions/runner/pull/2477#issuecomment-1501003600
  166. name: Export metadata
  167. if: fromJson(needs.prepare.outputs.push)
  168. run: |
  169. mkdir -p /tmp/metadata/builder /tmp/metadata/runner
  170. builderDigest=$(jq -r '."builder-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  171. touch "/tmp/metadata/builder/${builderDigest#sha256:}"
  172. runnerDigest=$(jq -r '."runner-${{ matrix.variant }}"."containerimage.digest"' <<< "${METADATA}")
  173. touch "/tmp/metadata/runner/${runnerDigest#sha256:}"
  174. env:
  175. METADATA: ${{ steps.build.outputs.metadata }}
  176. -
  177. name: Upload builder metadata
  178. if: fromJson(needs.prepare.outputs.push)
  179. uses: actions/upload-artifact@v3
  180. with:
  181. name: metadata-builder-${{ matrix.variant }}
  182. path: /tmp/metadata/builder/*
  183. if-no-files-found: error
  184. retention-days: 1
  185. -
  186. name: Upload runner metadata
  187. if: fromJson(needs.prepare.outputs.push)
  188. uses: actions/upload-artifact@v3
  189. with:
  190. name: metadata-runner-${{ matrix.variant }}
  191. path: /tmp/metadata/runner/*
  192. if-no-files-found: error
  193. retention-days: 1
  194. -
  195. name: Run tests
  196. if: ${{ !matrix.qemu && !fromJson(needs.prepare.outputs.push) }}
  197. run: |
  198. docker run --platform=${{ matrix.platform }} --rm \
  199. "$(jq -r '."builder-${{ matrix.variant }}"."containerimage.config.digest"' <<< "${METADATA}")" \
  200. sh -c 'go test ${{ matrix.race }} -v ./... && cd caddy && go test ${{ matrix.race }} -v ./...'
  201. env:
  202. METADATA: ${{ steps.build.outputs.metadata }}
  203. # Adapted from https://docs.docker.com/build/ci/github-actions/multi-platform/
  204. push:
  205. runs-on: ubuntu-latest
  206. needs:
  207. - prepare
  208. - build
  209. if: fromJson(needs.prepare.outputs.push)
  210. strategy:
  211. fail-fast: false
  212. matrix:
  213. variant: ${{ fromJson(needs.prepare.outputs.variants) }}
  214. target: ['builder', 'runner']
  215. steps:
  216. -
  217. name: Download metadata
  218. uses: actions/download-artifact@v3
  219. with:
  220. name: metadata-${{ matrix.target }}-${{ matrix.variant }}
  221. path: /tmp/metadata
  222. -
  223. name: Set up Docker Buildx
  224. uses: docker/setup-buildx-action@v3
  225. with:
  226. version: latest
  227. -
  228. name: Login to DockerHub
  229. uses: docker/login-action@v3
  230. with:
  231. username: ${{ secrets.REGISTRY_USERNAME }}
  232. password: ${{ secrets.REGISTRY_PASSWORD }}
  233. -
  234. name: Create manifest list and push
  235. working-directory: /tmp/metadata
  236. run: |
  237. # shellcheck disable=SC2046,SC2086
  238. docker buildx imagetools create $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | map("-t " + .) | join(" ")' <<< ${METADATA}) \
  239. $(printf 'dunglas/frankenphp@sha256:%s ' *)
  240. env:
  241. METADATA: ${{ needs.prepare.outputs.metadata }}
  242. -
  243. name: Inspect image
  244. run: |
  245. # shellcheck disable=SC2046,SC2086
  246. docker buildx imagetools inspect $(jq -cr '.target."${{ matrix.target }}-${{ matrix.variant }}".tags | first' <<< ${METADATA})
  247. env:
  248. METADATA: ${{ needs.prepare.outputs.metadata }}