e086f76da7
* ci: publish to PyPI via trusted publishing; build version images on release * ci: pin publish actions to commit SHAs; extend version guard to docker and manual dispatch * ci: disable setup-uv cache in the publish workflow
84 lines
2.8 KiB
YAML
84 lines
2.8 KiB
YAML
name: Docker
|
|
|
|
on:
|
|
push:
|
|
branches: ["main"]
|
|
# Version images build when a GitHub Release is published — the same event
|
|
# that triggers the PyPI upload (publish.yml), so the two channels stay in sync.
|
|
release:
|
|
types: [published]
|
|
pull_request:
|
|
paths:
|
|
- "Dockerfile"
|
|
- ".dockerignore"
|
|
- "pyproject.toml"
|
|
- "uv.lock"
|
|
- "EvoScientist/**"
|
|
- ".github/workflows/docker.yml"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: docker-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
REGISTRY: ghcr.io
|
|
IMAGE_NAME: ${{ github.repository }}
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 45
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
steps:
|
|
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
|
|
|
|
# Same guard as publish.yml — a release whose tag mismatches pyproject
|
|
# must not publish versioned images either.
|
|
- name: Guard — package version must match the release tag
|
|
if: github.event_name == 'release'
|
|
run: |
|
|
VERSION=$(grep -m1 '^version = ' pyproject.toml | sed -E 's/^version = "(.*)"/\1/')
|
|
TAG="${GITHUB_REF_NAME#v}"
|
|
echo "pyproject version: $VERSION | release tag: $TAG"
|
|
if [ "$VERSION" != "$TAG" ]; then
|
|
echo "::error::pyproject version ($VERSION) does not match release tag ($TAG); refusing to publish images."
|
|
exit 1
|
|
fi
|
|
|
|
- uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
|
|
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
|
|
|
|
- name: Log in to ${{ env.REGISTRY }}
|
|
if: github.event_name != 'pull_request'
|
|
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Extract image metadata
|
|
id: meta
|
|
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
|
|
with:
|
|
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
|
|
tags: |
|
|
type=ref,event=branch
|
|
type=ref,event=pr
|
|
type=semver,pattern={{version}}
|
|
type=semver,pattern={{major}}.{{minor}}
|
|
type=raw,value=latest,enable={{is_default_branch}}
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
|
|
with:
|
|
context: .
|
|
platforms: linux/amd64,linux/arm64
|
|
push: ${{ github.event_name != 'pull_request' }}
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|