Skip to content

Publish Docker Images #56

Publish Docker Images

Publish Docker Images #56

Workflow file for this run

name: Publish Docker Images
on:
push:
tags:
- "v*"
workflow_dispatch:
jobs:
build-images:
name: Build Docker Images
runs-on: ${{ matrix.platform == 'linux/arm64' && 'Linux-ARM64' || 'ubuntu-latest' }}
strategy:
matrix:
variant:
- name: "hub"
dockerfile: "Dockerfile"
suffix: ""
- name: "migrations"
dockerfile: "Dockerfile.db-based-migrations"
suffix: "-migrations"
platform: ["linux/amd64", "linux/arm64"]
permissions:
id-token: write
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to the GitHub Container registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Login to Docker Hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract platform architecture
id: platform
run: |
ARCH=$(echo "${{ matrix.platform }}" | cut -d'/' -f2)
echo "arch=${ARCH}" >> $GITHUB_OUTPUT
- name: Build and push Docker image (${{ matrix.variant.name }} - ${{ matrix.platform }})
uses: docker/build-push-action@v5
id: build
with:
context: .
file: ${{ matrix.variant.dockerfile }}
push: true
platforms: ${{ matrix.platform }}
outputs: type=image,name=ghcr.io/traceloop/hub${{ matrix.variant.suffix }},push-by-digest=true,name-canonical=true,push=true
provenance: false
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Export digest
run: |
mkdir -p /tmp/digests/${{ matrix.variant.name }}
digest="${{ steps.build.outputs.digest }}"
touch "/tmp/digests/${{ matrix.variant.name }}/${digest#sha256:}"
- name: Upload digest
uses: actions/upload-artifact@v4
with:
name: digests-${{ matrix.variant.name }}-${{ steps.platform.outputs.arch }}
path: /tmp/digests/${{ matrix.variant.name }}/*
if-no-files-found: error
retention-days: 1
create-manifests:
name: Create Multi-Arch Manifests
runs-on: ubuntu-latest
needs: build-images
strategy:
matrix:
variant:
- name: "hub"
suffix: ""
- name: "migrations"
suffix: "-migrations"
permissions:
contents: read
packages: write
steps:
- name: Download digests
uses: actions/download-artifact@v4
with:
path: /tmp/digests
pattern: digests-${{ matrix.variant.name }}-*
merge-multiple: true
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to the GitHub Container registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Login to Docker Hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract metadata for Docker
id: docker-metadata
uses: docker/metadata-action@v4
with:
images: |
ghcr.io/traceloop/hub${{ matrix.variant.suffix }}
traceloop/hub${{ matrix.variant.suffix }}
tags: |
type=sha
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
- name: Create and push multi-arch manifests (${{ matrix.variant.name }})
working-directory: /tmp/digests
run: |
# Get tags from metadata
TAGS="${{ steps.docker-metadata.outputs.tags }}"
# Create manifest list using digests
docker buildx imagetools create \
$(printf '%s\n' "$TAGS" | sed 's/^/--tag /' | tr '\n' ' ') \
$(printf 'ghcr.io/traceloop/hub${{ matrix.variant.suffix }}@sha256:%s ' *)
deploy:
name: Deploy to Traceloop
runs-on: ubuntu-latest
needs: create-manifests
steps:
- name: Install Octopus CLI
uses: OctopusDeploy/install-octopus-cli-action@v3
with:
version: "*"
- name: Create Octopus Release
env:
OCTOPUS_API_KEY: ${{ secrets.OCTOPUS_API_KEY }}
OCTOPUS_URL: ${{ secrets.OCTOPUS_URL }}
OCTOPUS_SPACE: ${{ secrets.OCTOPUS_SPACE }}
run: octopus release create --project hub --version=sha-${GITHUB_SHA::7} --packageVersion=sha-${GITHUB_SHA::7} --no-prompt
- name: Deploy Octopus release (Staging)
env:
OCTOPUS_API_KEY: ${{ secrets.OCTOPUS_API_KEY }}
OCTOPUS_URL: ${{ secrets.OCTOPUS_URL }}
OCTOPUS_SPACE: ${{ secrets.OCTOPUS_SPACE }}
run: octopus release deploy --project hub --version=sha-${GITHUB_SHA::7} --environment Staging --no-prompt
- name: Deploy Octopus release (staging-new)
env:
OCTOPUS_API_KEY: ${{ secrets.OCTOPUS_API_KEY }}
OCTOPUS_URL: ${{ secrets.OCTOPUS_URL }}
OCTOPUS_SPACE: ${{ secrets.OCTOPUS_SPACE }}
run: octopus release deploy --project hub --version=sha-${GITHUB_SHA::7} --environment staging-new --no-prompt
push-helm-chart:
name: Push Helm Chart to Dockerhub
runs-on: ubuntu-latest
needs: create-manifests
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Get Chart Version
id: chartVersion
run: |
CHART_VERSION=$(grep '^version:' helm/Chart.yaml | awk '{print $2}')
echo "CHART_VERSION=$CHART_VERSION"
echo "chart_version=$CHART_VERSION" >> $GITHUB_OUTPUT
- name: Get Chart Name
id: chartName
run: |
CHART_NAME=$(grep '^name:' helm/Chart.yaml | awk '{print $2}')
echo "CHART_NAME=$CHART_NAME"
echo "chart_name=$CHART_NAME" >> $GITHUB_OUTPUT
- name: Login to Docker Hub as OCI registry
run: |
echo "${{ secrets.DOCKERHUB_TOKEN }}" | helm registry login registry-1.docker.io \
--username "${{ secrets.DOCKERHUB_USERNAME }}" \
--password-stdin
- name: Package Helm chart
run: |
helm package helm/
- name: Push Helm Chart
run: |
helm push "${{ steps.chartName.outputs.chart_name }}-${{ steps.chartVersion.outputs.chart_version }}.tgz" oci://registry-1.docker.io/traceloop