Skip to content

ci: read the CodeQL ROCm image from the Dockerfile #286

ci: read the CodeQL ROCm image from the Dockerfile

ci: read the CodeQL ROCm image from the Dockerfile #286

Workflow file for this run

name: CI
on:
pull_request:
push:
branches:
- main
tags:
- "v*"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
IMAGE_NAME: ghcr.io/project-hami/amd-device-plugin
BUILDER_IMAGE: amd-device-plugin-builder:${{ github.sha }}
jobs:
test:
name: Build and test
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: true
persist-credentials: false
- name: Verify amd-hami-core submodule
run: |
test -d ./amd-hami-core
test -f ./amd-hami-core/Makefile.hip
test -f ./amd-hami-core/CMakeLists.txt.hip
test -d ./amd-hami-core/src
test -s ./scripts/amd-vgpu-init.sh
sh -n ./scripts/amd-vgpu-init.sh
# The package uses cgo with AMD SMI and libdrm_amdgpu. Reusing the
# Dockerfile builder keeps CI on the exact SDK used by release images.
- name: Build cgo builder image
run: docker build --target builder --tag "${BUILDER_IMAGE}" .
- name: Run unit tests in AMD SMI builder
run: >-
docker run --rm
--workdir /go/src/github.com/Project-HAMi/amd-device-plugin
--env LD_LIBRARY_PATH=/opt/rocm/lib
"${BUILDER_IMAGE}"
bash -c 'ln -sf libamd_smi.so /opt/rocm/lib/libamd_smi.so.26 && go vet ./... && go test -race ./...'
helm:
name: Lint Helm chart
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: true
persist-credentials: false
- name: Install Helm
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5
with:
version: v3.20.2
- name: Lint chart
run: helm lint ./helm/amd-gpu
- name: Render chart
run: |
helm template amd-gpu ./helm/amd-gpu --namespace kube-system >/dev/null
# the optional branches render too
helm template amd-gpu ./helm/amd-gpu --namespace kube-system \
--set dp.cdi.enabled=true,dp.muslFailClosed.enabled=true,node_selector_enabled=true >/dev/null
# Build-only checks so the images that CI does not publish cannot silently break.
extra-images:
name: Build ${{ matrix.dockerfile }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
dockerfile:
- labeller.Dockerfile
- ubi-dp.Dockerfile
- ubi-labeller.Dockerfile
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: true
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
- name: Build image
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7
with:
context: .
file: ${{ matrix.dockerfile }}
platforms: linux/amd64
push: false
cache-from: type=gha,scope=${{ matrix.dockerfile }}
cache-to: type=gha,mode=max,scope=${{ matrix.dockerfile }}
image:
name: Build and publish image
needs:
- test
- helm
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write
attestations: write
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
submodules: true
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
- name: Generate image metadata
id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6
with:
images: ${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=sha
- name: Log in to GitHub Container Registry
if: github.event_name != 'pull_request'
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and optionally publish image
id: build
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7
with:
context: .
platforms: linux/amd64
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Attest build provenance
if: github.event_name != 'pull_request'
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ${{ env.IMAGE_NAME }}
subject-digest: ${{ steps.build.outputs.digest }}
push-to-registry: true