diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml new file mode 100644 index 0000000..7d456dd --- /dev/null +++ b/.github/workflows/docker-publish.yml @@ -0,0 +1,84 @@ +name: Docker publish + +on: + schedule: + # @weekly + - cron: "0 0 * * SUN" + push: + branches: ["main"] + +jobs: + publish: + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + id-token: write + strategy: + matrix: + distro: [ubuntu] + env: + REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository_owner }}/${{ matrix.distro }} + + steps: + # Docker build using Git context, no need to use checkout action + # - name: Checkout repository + # uses: actions/checkout@v4 + + # Add support for more platforms with QEMU (optional) + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + # By default, builder driver is `docker`, which currently not supported + # building multi-platform images or exporting cache. + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into ${{ env.REGISTRY }} + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v5 + env: + DOCKER_METADATA_ANNOTATIONS_LEVELS: manifest,index + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=raw,value=22.04 + labels: | + org.opencontainers.image.title=Ubuntu 22.04 Actions runner images + org.opencontainers.image.description=Ubuntu 22.04 docker image used of (GitHub) Actions runner + annotations: | + org.opencontainers.image.title=Ubuntu 22.04 Actions runner images + org.opencontainers.image.description=Ubuntu 22.04 docker image used of (GitHub) Actions runner + + - name: Docker builder info + run: | + set -x + docker buildx version + docker buildx ls + docker buildx inspect + + - name: Build and push Docker image + id: publish + uses: docker/build-push-action@v6 + with: + pull: true + push: true + sbom: true + provenance: true + context: "{{defaultContext}}:${{ matrix.distro }}" + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + annotations: ${{ steps.meta.outputs.annotations }} + cache-from: type=gha + cache-to: type=gha,mode=max + platforms: | + linux/amd64 + linux/arm64