Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,9 @@ on:
env:
CARGO_TERM_COLOR: 'always'

permissions:
contents: read

jobs:
test:
runs-on: ubuntu-latest
Expand Down
181 changes: 142 additions & 39 deletions .github/workflows/docker-build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,56 +2,159 @@ name: Docker Image Build

on:
pull_request:
types:
- opened
- reopened
- synchronize
- closed
push:
branches:
- main
release:
types: [published]
workflow_dispatch:

env:
REGISTRY: quay.io
IMAGE: quay.io/stackmon/metrics-processor
REGISTRY: swr.eu-de.otc.t-systems.com
PROJECT: metrics-processor
# OTC project of the region, listed under "My Credentials > API Credentials" in the OTC console.
SWR_PROJECT: eu-de

permissions:
contents: read

jobs:

build:
if: github.event.pull_request.merged != true
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
env:
ORG: stackmon-preprod

steps:
- uses: actions/checkout@v7
- uses: actions/checkout@v7

- name: Docker meta
id: meta
uses: docker/metadata-action@v5
with:
images: |
${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }}
tags: |
type=ref,event=pr

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Build image
uses: docker/build-push-action@v7
with:
context: .
target: metrics-processor
push: false
- name: Build
uses: docker/build-push-action@v7
with:
context: .
target: metrics-processor
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
push: false

push_if_merged:
# The tag is pinned by stackmon-config/config.yaml, keep change_<pr>_latest.
if: github.event.pull_request.merged == true
# Builds from main and manual runs land in the preprod project; only a release reaches stackmon.
publish-preprod:
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
env:
ORG: stackmon-preprod

steps:
- uses: actions/checkout@v7

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Login to Container Registry
uses: docker/login-action@v4
with:
registry: ${{ env.REGISTRY }}
username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}

- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
target: metrics-processor
push: true
tags: ${{ env.IMAGE }}:change_${{ github.event.pull_request.number }}_latest
- uses: actions/checkout@v7

- name: Docker meta
id: meta
uses: docker/metadata-action@v5
with:
images: |
${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }}
tags: |
type=sha

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Login to Container Registry
env:
SWR_AK: ${{ secrets.SWR_PREPROD_AK }}
SWR_SK: ${{ secrets.SWR_PREPROD_SK }}
run: |
set -euo pipefail

if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then
echo "The SWR_PREPROD_AK and SWR_PREPROD_SK repository secrets must be set" >&2
exit 1
fi

# SWR authenticates with "<project>@<AK>" and a login key derived from the AK/SK pair.
login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')"
if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then
echo "Cannot derive the SWR login key from the AK/SK pair" >&2
exit 1
fi

printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin

- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
target: metrics-processor
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
# SWR rejects the OCI image index and attestation manifests that BuildKit adds by default.
provenance: false
sbom: false
push: true

publish:
if: github.event_name == 'release'
runs-on: ubuntu-latest
env:
ORG: stackmon

steps:
- uses: actions/checkout@v7

- name: Docker meta
id: meta
uses: docker/metadata-action@v5
with:
images: |
${{ env.REGISTRY }}/${{ env.ORG }}/${{ env.PROJECT }}
tags: |
type=semver,pattern=v{{version}}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Login to Container Registry
env:
SWR_AK: ${{ secrets.SWR_AK }}
SWR_SK: ${{ secrets.SWR_SK }}
run: |
set -euo pipefail

if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then
echo "The SWR_AK and SWR_SK repository secrets must be set" >&2
exit 1
fi

# SWR authenticates with "<project>@<AK>" and a login key derived from the AK/SK pair.
login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')"
if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then
echo "Cannot derive the SWR login key from the AK/SK pair" >&2
exit 1
fi

printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin

- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
target: metrics-processor
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
# SWR rejects the OCI image index and attestation manifests that BuildKit adds by default.
provenance: false
sbom: false
push: true
Loading