diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a284523..216511e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,6 +10,9 @@ on: env: CARGO_TERM_COLOR: 'always' +permissions: + contents: read + jobs: test: runs-on: ubuntu-latest diff --git a/.github/workflows/docker-build.yaml b/.github/workflows/docker-build.yaml index 007653d..d1e445b 100644 --- a/.github/workflows/docker-build.yaml +++ b/.github/workflows/docker-build.yaml @@ -2,56 +2,159 @@ name: Docker Image Build on: pull_request: - types: - - opened - - reopened - - synchronize - - closed + push: + branches: + - main + release: + types: [published] + workflow_dispatch: env: - REGISTRY: quay.io - IMAGE: quay.io/stackmon/metrics-processor + REGISTRY: swr.eu-de.otc.t-systems.com + PROJECT: metrics-processor + # OTC project of the region, listed under "My Credentials > API Credentials" in the OTC console. + SWR_PROJECT: eu-de + +permissions: + contents: read jobs: + build: - if: github.event.pull_request.merged != true + if: github.event_name == 'pull_request' runs-on: ubuntu-latest + env: + ORG: stackmon-preprod steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7 + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }} + tags: | + type=ref,event=pr - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 - - name: Build image - uses: docker/build-push-action@v7 - with: - context: . - target: metrics-processor - push: false + - name: Build + uses: docker/build-push-action@v7 + with: + context: . + target: metrics-processor + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + push: false - push_if_merged: - # The tag is pinned by stackmon-config/config.yaml, keep change__latest. - if: github.event.pull_request.merged == true + # Builds from main and manual runs land in the preprod project; only a release reaches stackmon. + publish-preprod: + if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest + env: + ORG: stackmon-preprod steps: - - uses: actions/checkout@v7 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Login to Container Registry - uses: docker/login-action@v4 - with: - registry: ${{ env.REGISTRY }} - username: ${{ secrets.REGISTRY_USER }} - password: ${{ secrets.REGISTRY_PASSWORD }} - - - name: Build and push - uses: docker/build-push-action@v7 - with: - context: . - target: metrics-processor - push: true - tags: ${{ env.IMAGE }}:change_${{ github.event.pull_request.number }}_latest + - uses: actions/checkout@v7 + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }} + tags: | + type=sha + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to Container Registry + env: + SWR_AK: ${{ secrets.SWR_PREPROD_AK }} + SWR_SK: ${{ secrets.SWR_PREPROD_SK }} + run: | + set -euo pipefail + + if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then + echo "The SWR_PREPROD_AK and SWR_PREPROD_SK repository secrets must be set" >&2 + exit 1 + fi + + # SWR authenticates with "@" and a login key derived from the AK/SK pair. + login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" + if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then + echo "Cannot derive the SWR login key from the AK/SK pair" >&2 + exit 1 + fi + + printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin + + - name: Build and push + uses: docker/build-push-action@v7 + with: + context: . + target: metrics-processor + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + # SWR rejects the OCI image index and attestation manifests that BuildKit adds by default. + provenance: false + sbom: false + push: true + + publish: + if: github.event_name == 'release' + runs-on: ubuntu-latest + env: + ORG: stackmon + + steps: + - uses: actions/checkout@v7 + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }} + tags: | + type=semver,pattern=v{{version}} + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to Container Registry + env: + SWR_AK: ${{ secrets.SWR_AK }} + SWR_SK: ${{ secrets.SWR_SK }} + run: | + set -euo pipefail + + if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then + echo "The SWR_AK and SWR_SK repository secrets must be set" >&2 + exit 1 + fi + + # SWR authenticates with "@" and a login key derived from the AK/SK pair. + login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" + if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then + echo "Cannot derive the SWR login key from the AK/SK pair" >&2 + exit 1 + fi + + printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin + + - name: Build and push + uses: docker/build-push-action@v7 + with: + context: . + target: metrics-processor + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + # SWR rejects the OCI image index and attestation manifests that BuildKit adds by default. + provenance: false + sbom: false + push: true