119 lines
4.1 KiB
YAML
119 lines
4.1 KiB
YAML
# Builds the image the `pwsh` job of ci.yml runs in: Debian, PowerShell 7 and PSScriptAnalyzer
|
|
# (Gitea #151, D37). It lives in this Gitea instance's registry as
|
|
# `gitea.nehmer.net/torben/chemenu-ci-pwsh`.
|
|
#
|
|
# The image follows the current PowerShell release, not a pin: users run whatever pwsh is
|
|
# current, so that is what the preflight has to be tested against. A change to the Dockerfile
|
|
# or to this file rebuilds it, a month turning over rebuilds it so the Debian layers do not age
|
|
# unnoticed, and a run triggered by hand can build an older release with `pwsh_version`.
|
|
#
|
|
# Tags: `:<pwsh-version>` always, `:latest` only when that version is the current release.
|
|
#
|
|
# Runner shape follows `sp-live-image.yml`: the `container-builder` label, a remote BuildKit
|
|
# on the runner host, and the registry login from 1Password.
|
|
#
|
|
# After the very first push the package has to be linked to this repository once, by hand, in
|
|
# the Gitea UI - a step no workflow can do. Until then the image builds and pulls fine; only
|
|
# the package page shows no repository.
|
|
|
|
name: pwsh CI image
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- '.gitea/pwsh-ci/**'
|
|
- '.gitea/workflows/pwsh-ci-image.yml'
|
|
schedule:
|
|
- cron: '30 4 1 * *'
|
|
workflow_dispatch:
|
|
inputs:
|
|
pwsh_version:
|
|
description: 'PowerShell release to build (default: the current one)'
|
|
required: false
|
|
|
|
env:
|
|
REGISTRY: gitea.nehmer.net/torben
|
|
IMAGE_NAME: chemenu-ci-pwsh
|
|
|
|
jobs:
|
|
build-and-push:
|
|
runs-on: container-builder
|
|
container:
|
|
image: debian:trixie-slim
|
|
steps:
|
|
- name: Install CI dependencies
|
|
# `nodejs` is for act_runner's JavaScript actions, `unzip` for
|
|
# 1password/load-secrets-action - see sp-live-image.yml.
|
|
run: |
|
|
set -eu
|
|
apt-get update -qq
|
|
apt-get install -y --no-install-recommends \
|
|
git nodejs curl docker-cli docker-buildx unzip ca-certificates iproute2 gawk
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Resolve the PowerShell release
|
|
id: pwsh
|
|
env:
|
|
REQUESTED: ${{ inputs.pwsh_version }}
|
|
run: |
|
|
set -eu
|
|
current="$(curl -fsSL https://api.github.com/repos/PowerShell/PowerShell/releases/latest \
|
|
| sed -n 's/.*"tag_name": *"v\([^"]*\)".*/\1/p' | head -n 1)"
|
|
test -n "$current"
|
|
wanted="${REQUESTED:-$current}"
|
|
{
|
|
echo "version=$wanted"
|
|
echo "current=$current"
|
|
} >> "$GITHUB_OUTPUT"
|
|
echo "wanted $wanted, current $current"
|
|
|
|
- name: Load secrets from 1Password
|
|
uses: 1password/load-secrets-action@v2
|
|
with:
|
|
export-env: true
|
|
env:
|
|
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }}
|
|
REGISTRY_USER: op://CI-CD/gitea-package-token/username
|
|
REGISTRY_PAT: op://CI-CD/gitea-package-token/password
|
|
|
|
- name: BuildKit setup (remote builder)
|
|
run: |
|
|
HOST_IP=$(ip route | awk '/default/ { print $3 }')
|
|
docker buildx create --name remote-builder --driver remote tcp://$HOST_IP:1234 --use --bootstrap
|
|
|
|
- name: Log in to the container registry
|
|
run: |
|
|
echo "$REGISTRY_PAT" | docker login gitea.nehmer.net -u "$REGISTRY_USER" --password-stdin
|
|
|
|
- name: Decide the tags
|
|
id: decide
|
|
env:
|
|
PWSH_VERSION: ${{ steps.pwsh.outputs.version }}
|
|
CURRENT: ${{ steps.pwsh.outputs.current }}
|
|
run: |
|
|
set -eu
|
|
tags="$REGISTRY/$IMAGE_NAME:$PWSH_VERSION"
|
|
if [ "$PWSH_VERSION" = "$CURRENT" ]; then
|
|
tags="$tags
|
|
$REGISTRY/$IMAGE_NAME:latest"
|
|
fi
|
|
{
|
|
echo "tags<<EOF"
|
|
echo "$tags"
|
|
echo "EOF"
|
|
} >> "$GITHUB_OUTPUT"
|
|
echo "tags: $tags"
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v6
|
|
with:
|
|
context: .gitea/pwsh-ci
|
|
file: .gitea/pwsh-ci/Dockerfile
|
|
platforms: linux/amd64
|
|
push: true
|
|
tags: ${{ steps.decide.outputs.tags }}
|
|
build-args: |
|
|
PWSH_VERSION=${{ steps.pwsh.outputs.version }}
|