ci: Support for upload/download-artifact@4 action #78
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# See https://docs.docker.com/build/ci/github-actions/multi-platform/ | |
name: Docker | |
on: | |
push: | |
branches: | |
- main | |
tags: | |
- v* | |
pull_request: | |
branches: | |
- '*' | |
permissions: | |
contents: read | |
id-token: write | |
env: | |
REGISTRY_IMAGE: grafana/tanka | |
# Docker image tags. See https://github.com/docker/metadata-action for format | |
TAGS_CONFIG: | | |
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }} | |
type=sha,prefix={{branch}}-,format=short,enable=${{ github.ref == 'refs/heads/main' }} | |
type=semver,pattern={{version}} | |
jobs: | |
build: | |
runs-on: ubuntu-latest | |
strategy: | |
fail-fast: false | |
matrix: | |
platform: | |
- linux/amd64 | |
- linux/arm64 | |
steps: | |
- name: Checkout | |
uses: actions/checkout@v4 | |
- name: Docker meta | |
id: meta | |
uses: docker/metadata-action@v5 | |
with: | |
images: ${{ env.REGISTRY_IMAGE }} | |
tags: ${{ env.TAGS_CONFIG }} | |
# Setup buildx | |
- name: Set up QEMU | |
uses: docker/setup-qemu-action@v3 | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
# Login to Docker Hub | |
- name: Get Secrets | |
if: github.event_name != 'pull_request' | |
uses: grafana/shared-workflows/actions/get-vault-secrets@main | |
with: | |
# Secrets placed in the ci/common/<path> path in Vault | |
common_secrets: | | |
DOCKERHUB_USERNAME=dockerhub:username | |
DOCKERHUB_TOKEN=dockerhub:password | |
- name: Login to Docker Hub | |
if: github.event_name != 'pull_request' | |
uses: docker/login-action@v3 | |
with: | |
username: ${{ env.DOCKERHUB_USERNAME }} | |
password: ${{ env.DOCKERHUB_TOKEN }} | |
- name: Build and push by digest | |
id: build | |
uses: docker/build-push-action@v5 | |
with: | |
context: . | |
platforms: ${{ matrix.platform }} | |
labels: ${{ steps.meta.outputs.labels }} | |
outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=${{ github.event_name != 'pull_request' }} | |
- name: Export digest | |
id: digest | |
# TODO: Enable once tested | |
# if: github.event_name != 'pull_request' | |
run: | | |
mkdir -p /tmp/digests | |
digest="${{ steps.build.outputs.digest }}" | |
touch "/tmp/digests/${digest#sha256:}" | |
echo "artifact_name=${{ matrix.platform }}" | sed -e 's/\//-/g' >> "$GITHUB_OUTPUT" | |
- name: Upload digest | |
# TODO: Enable once tested | |
# if: github.event_name != 'pull_request' | |
uses: actions/upload-artifact@v4 | |
with: | |
name: ${{ steps.digest.outputs.artifact_name }} | |
path: /tmp/digests/* | |
if-no-files-found: error | |
retention-days: 1 | |
merge: | |
runs-on: ubuntu-latest | |
# Temporary enable also for PRs to test this change | |
# if: github.event_name != 'pull_request' | |
needs: | |
- build | |
steps: | |
- name: Download digests (linux/amd64) | |
uses: actions/download-artifact@v4 | |
with: | |
name: digests-linux-amd64 | |
path: /tmp/digests-linux-amd64 | |
- name: Download digests (linux/arm64) | |
uses: actions/download-artifact@v4 | |
with: | |
name: digests-linux-arm64 | |
path: /tmp/digests-linux-arm64 | |
- name: Merge digests | |
run: | | |
mkdir -p /tmp/digests | |
cp /tmp/digests-linux-amd64/* /tmp/digests/ | |
cp /tmp/digests-linux-arm64/* /tmp/digests/ | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
- name: Docker meta | |
id: meta | |
uses: docker/metadata-action@v5 | |
with: | |
images: ${{ env.REGISTRY_IMAGE }} | |
tags: ${{ env.TAGS_CONFIG }} | |
# Login to Docker Hub | |
- name: Get Secrets | |
# TODO: Remove once tested | |
if: github.event_name != 'pull_request' | |
uses: grafana/shared-workflows/actions/get-vault-secrets@main | |
with: | |
# Secrets placed in the ci/common/<path> path in Vault | |
common_secrets: | | |
DOCKERHUB_USERNAME=dockerhub:username | |
DOCKERHUB_TOKEN=dockerhub:password | |
- name: Login to Docker Hub | |
# TODO: Remove once tested | |
if: github.event_name != 'pull_request' | |
uses: docker/login-action@v3 | |
with: | |
username: ${{ env.DOCKERHUB_USERNAME }} | |
password: ${{ env.DOCKERHUB_TOKEN }} | |
- name: Create manifest list and push | |
# TODO: Remove once tested | |
if: github.event_name != 'pull_request' | |
working-directory: /tmp/digests | |
run: | | |
docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ | |
$(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *) | |
- name: Inspect image | |
# TODO: Remove once tested | |
if: github.event_name != 'pull_request' | |
run: | | |
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.meta.outputs.version }} |