2023-01-30 10:11:27 -05:00
|
|
|
# Required permissions:
|
|
|
|
#
|
|
|
|
# permissions:
|
|
|
|
# packages: write # for docker/build-push-action
|
|
|
|
#
|
2022-07-13 08:04:46 -04:00
|
|
|
name: Build micro service
|
2022-06-15 04:50:46 -04:00
|
|
|
description: Build and upload a container image for a Constellation micro-service
|
|
|
|
inputs:
|
|
|
|
name:
|
2022-09-14 09:14:26 -04:00
|
|
|
description: "Name of the micro-service"
|
2022-06-15 04:50:46 -04:00
|
|
|
required: true
|
2022-06-15 05:15:33 -04:00
|
|
|
projectVersion:
|
2022-09-14 09:14:26 -04:00
|
|
|
description: "Version of the micro-service"
|
|
|
|
default: "0.0.0"
|
2022-06-15 05:15:33 -04:00
|
|
|
required: false
|
2022-06-15 04:50:46 -04:00
|
|
|
dockerfile:
|
2022-09-14 09:14:26 -04:00
|
|
|
description: "Path to the services Dockerfile"
|
2022-06-15 04:50:46 -04:00
|
|
|
required: true
|
|
|
|
pushTag:
|
2022-09-14 09:14:26 -04:00
|
|
|
description: "Use this image tag"
|
2022-06-15 04:50:46 -04:00
|
|
|
required: false
|
|
|
|
githubToken:
|
2022-09-14 09:14:26 -04:00
|
|
|
description: "GitHub authorization token"
|
2022-06-15 04:50:46 -04:00
|
|
|
required: true
|
2022-10-21 09:19:51 -04:00
|
|
|
cosignPublicKey:
|
|
|
|
description: "Cosign public key"
|
|
|
|
required: false
|
|
|
|
cosignPrivateKey:
|
|
|
|
description: "Cosign private key"
|
|
|
|
required: false
|
|
|
|
cosignPassword:
|
|
|
|
description: "Password for Cosign private key"
|
|
|
|
required: false
|
2022-06-15 04:50:46 -04:00
|
|
|
|
2022-09-14 09:14:26 -04:00
|
|
|
# Linux runner only (Docker required)
|
2022-07-13 08:04:46 -04:00
|
|
|
runs:
|
2022-06-15 04:50:46 -04:00
|
|
|
using: "composite"
|
|
|
|
steps:
|
2022-07-14 09:45:04 -04:00
|
|
|
- name: Determine pseudo version
|
|
|
|
id: pseudo-version
|
|
|
|
uses: ./.github/actions/pseudo_version
|
|
|
|
|
2022-06-15 04:50:46 -04:00
|
|
|
- name: Docker metadata
|
|
|
|
id: meta
|
2024-02-21 09:29:06 -05:00
|
|
|
uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5.5.1
|
2022-06-15 04:50:46 -04:00
|
|
|
with:
|
|
|
|
images: |
|
|
|
|
ghcr.io/${{ github.repository }}/${{ inputs.name }}
|
|
|
|
tags: |
|
|
|
|
type=raw,value=latest,enable={{is_default_branch}}
|
|
|
|
type=raw,value=${{ inputs.pushTag }},enable=${{ '' != inputs.pushTag }}
|
2023-03-14 09:53:33 -04:00
|
|
|
type=raw,value=${{ steps.pseudo-version.outputs.version }},enable=${{ '' != steps.pseudo-version.outputs.version }}
|
2022-06-15 04:50:46 -04:00
|
|
|
type=ref,event=branch
|
2022-11-30 11:20:16 -05:00
|
|
|
|
2022-06-15 04:50:46 -04:00
|
|
|
- name: Log in to the Container registry
|
|
|
|
id: docker-login
|
2023-06-06 06:20:09 -04:00
|
|
|
uses: ./.github/actions/container_registry_login
|
2022-06-15 04:50:46 -04:00
|
|
|
with:
|
|
|
|
registry: ghcr.io
|
|
|
|
username: ${{ github.actor }}
|
|
|
|
password: ${{ inputs.githubToken }}
|
|
|
|
|
|
|
|
- name: Build and push container image
|
|
|
|
id: build-micro-service
|
2024-06-19 09:19:41 -04:00
|
|
|
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0
|
2022-06-15 04:50:46 -04:00
|
|
|
with:
|
|
|
|
context: .
|
|
|
|
file: ${{ inputs.dockerfile }}
|
|
|
|
target: release
|
|
|
|
push: true
|
|
|
|
tags: ${{ steps.meta.outputs.tags }}
|
2022-06-15 05:15:33 -04:00
|
|
|
build-args: |
|
|
|
|
PROJECT_VERSION=${{ inputs.projectVersion }}
|
2022-10-21 09:19:51 -04:00
|
|
|
|
|
|
|
- name: Generate SBOM
|
2023-01-18 04:15:58 -05:00
|
|
|
if: inputs.cosignPublicKey != '' && inputs.cosignPrivateKey != '' && inputs.cosignPassword != ''
|
2022-10-21 09:19:51 -04:00
|
|
|
uses: ./.github/actions/container_sbom
|
|
|
|
with:
|
|
|
|
containerReference: ghcr.io/${{ github.repository }}/${{ inputs.name }}@${{ steps.build-micro-service.outputs.digest }}
|
|
|
|
cosignPublicKey: ${{ inputs.cosignPublicKey }}
|
|
|
|
cosignPrivateKey: ${{ inputs.cosignPrivateKey }}
|
|
|
|
cosignPassword: ${{ inputs.cosignPassword }}
|