Skip to content

BAH-4114 | Fix. Bump Vulnerable Base Image Version (#18) #40

BAH-4114 | Fix. Bump Vulnerable Base Image Version (#18)

BAH-4114 | Fix. Bump Vulnerable Base Image Version (#18) #40

name: Build and Publish bahmni-metabase Image
on:
push:
branches: main
tags:
- '[0-9]+.[0-9]+.[0-9]+'
jobs:
Trivy:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Trivy Scan
run: ./.github/trivy_scan.sh
build-publish-docker-helm:
name: Build & Publish Docker Image & Helm Chart
runs-on: ubuntu-latest
env:
HELM_CHART_PATH: package/helm
needs: Trivy
steps:
- uses: actions/checkout@v2
- name: Set env.ARTIFACT_VERSION
run: |
wget -q https://raw.githubusercontent.com/Bahmni/bahmni-infra-utils/main/setArtifactVersion.sh && chmod +x setArtifactVersion.sh
./setArtifactVersion.sh
rm setArtifactVersion.sh
- name: Login to DockerHub
uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKER_HUB_USERNAME }}
password: ${{ secrets.DOCKER_HUB_TOKEN }}
- name: Docker Build and push
uses: docker/build-push-action@v2
with:
context: package/docker/
no-cache: true
push: true
tags: bahmni/bahmni-metabase:${{env.ARTIFACT_VERSION}},bahmni/bahmni-metabase:latest
- name: Helm - Update Version and Image Tag
run: |
yq --inplace '.image.tag = "${{ env.ARTIFACT_VERSION }}"' $HELM_CHART_PATH/values.yaml
yq --inplace '.version = "${{ env.ARTIFACT_VERSION }}"' $HELM_CHART_PATH/Chart.yaml
- name: Helm Lint
run: helm lint $HELM_CHART_PATH
- name: Helm Package
run: helm package $HELM_CHART_PATH
- name: Helm - Checkout Charts Repository
uses: actions/checkout@v2
with:
repository: Bahmni/helm-charts
ref: gh-pages
path: helm-charts
persist-credentials: false
- name: Helm - Copy chart
run: mkdir -p helm-charts/bahmni-metabase/ && cp bahmni-metabase-${{ env.ARTIFACT_VERSION }}.tgz helm-charts/bahmni-metabase/
- name: Helm - Index
working-directory: helm-charts/
run: helm repo index --merge index.yaml --url https://bahmni.github.io/helm-charts/ .
- name: Helm - Publish Chart
working-directory: helm-charts/
run: |
git config user.name ${{ secrets.BAHMNI_USERNAME}}
git config user.email ${{ secrets.BAHMNI_EMAIL}}
git add .
git commit -m "Release of bahmni-metabase-${{ env.ARTIFACT_VERSION }}"
git push 'https://${{ secrets.BAHMNI_USERNAME}}:${{ secrets.BAHMNI_PAT}}@github.com/bahmni/helm-charts.git' gh-pages