2022-08-09 10:33:37 -04:00
|
|
|
name: Build and Upload GCP guest-agent container
|
2023-03-01 07:52:52 -05:00
|
|
|
|
|
|
|
on:
|
|
|
|
workflow_dispatch:
|
|
|
|
schedule:
|
|
|
|
- cron: "0 4 * * 2" # Every Tuesday at 4am UTC
|
|
|
|
|
2022-08-09 10:33:37 -04:00
|
|
|
env:
|
|
|
|
REGISTRY: ghcr.io
|
|
|
|
|
|
|
|
jobs:
|
|
|
|
build-gcp-guest-agent:
|
2022-11-10 10:55:24 -05:00
|
|
|
runs-on: ubuntu-22.04
|
2022-08-09 10:33:37 -04:00
|
|
|
permissions:
|
|
|
|
contents: read
|
|
|
|
packages: write
|
2023-03-01 07:52:52 -05:00
|
|
|
|
2022-08-09 10:33:37 -04:00
|
|
|
steps:
|
2023-03-01 07:52:52 -05:00
|
|
|
- name: Get latest release of guest-agent
|
|
|
|
id: latest-release
|
|
|
|
run: |
|
|
|
|
latest=$(curl -fsSL https://api.github.com/repos/GoogleCloudPlatform/guest-agent/releases/latest | jq -r .tag_name)
|
|
|
|
echo "Latest version of guest-agent is $latest"
|
2023-04-14 12:25:53 -04:00
|
|
|
echo "latest=$latest" | tee -a "$GITHUB_OUTPUT"
|
2023-03-01 07:52:52 -05:00
|
|
|
|
2023-03-10 10:44:42 -05:00
|
|
|
- name: Make tag a valid semver
|
|
|
|
id: latest-release-semver
|
|
|
|
run: |
|
|
|
|
semver="${{ steps.latest-release.outputs.latest }}"
|
|
|
|
beforeDot="${semver%%.*}"
|
|
|
|
afterDot="${semver#*.}"
|
|
|
|
afterDotEvaluated=$((afterDot))
|
2023-05-11 08:20:21 -04:00
|
|
|
semver="v${beforeDot}.${afterDotEvaluated}.0"
|
2023-03-10 10:44:42 -05:00
|
|
|
echo "Semver tag of guest-agent is $semver"
|
2023-04-14 12:25:53 -04:00
|
|
|
echo "latest=$semver" | tee -a "$GITHUB_OUTPUT"
|
2023-03-10 10:44:42 -05:00
|
|
|
|
2023-03-10 11:36:18 -05:00
|
|
|
- name: Check if the tag is newer than our last build
|
|
|
|
id: needs-build
|
|
|
|
run: |
|
|
|
|
apiURL="https://ghcr.io/v2/edgelesssys/gcp-guest-agent"
|
|
|
|
tokenJSON=$(curl -fsSL "https://ghcr.io/token?scope=repository:edgelesssys/gcp-guest-agent:pull")
|
|
|
|
token=$(jq -r '.token' <<< "$tokenJSON")
|
|
|
|
tokenHeader=(-H "Authorization: Bearer ${token}")
|
|
|
|
|
|
|
|
tags=$(curl -fsSL "${tokenHeader[@]}" "${apiURL}/tags/list")
|
|
|
|
semverUpstream="${{ steps.latest-release-semver.outputs.latest }}"
|
|
|
|
|
|
|
|
rebuild=false
|
|
|
|
|
|
|
|
if [[ $(jq -r '.tags | index("latest")' <<< "$tags") == 'null' ]]; then
|
|
|
|
rebuild=true
|
|
|
|
elif [[ $(jq -r '.tags | index("${{ steps.latest-release-semver.outputs.latest }}")' <<< "$tags") == 'null' ]]; then
|
|
|
|
rebuild=true
|
|
|
|
else
|
|
|
|
digestLatest=$(curl -fsSL "${tokenHeader[@]}" "${apiURL}/manifests/latest" | jq -r '.config.digest')
|
|
|
|
digestSemver=$(curl -fsSL "${tokenHeader[@]}" "${apiURL}/manifests/${semverUpstream}" | jq -r '.config.digest')
|
|
|
|
if [[ "$digestLatest" != "$digestSemver" ]]; then
|
|
|
|
rebuild=true
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [[ $rebuild == false ]]; then
|
|
|
|
echo "Latest tag $latestTag is already built, exiting"
|
2023-04-14 12:25:53 -04:00
|
|
|
echo "out=false" | tee -a "$GITHUB_OUTPUT"
|
2023-03-10 11:36:18 -05:00
|
|
|
exit 0
|
|
|
|
fi
|
|
|
|
echo "Latest tag $latestTag is older than ${semverUpstream}, building"
|
2023-04-14 12:25:53 -04:00
|
|
|
echo "out=true" | tee -a "$GITHUB_OUTPUT"
|
2023-03-10 11:36:18 -05:00
|
|
|
|
2023-01-18 04:15:58 -05:00
|
|
|
- name: Checkout GoogleCloudPlatform/guest-agent
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2023-07-03 02:19:10 -04:00
|
|
|
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
|
2022-08-09 10:33:37 -04:00
|
|
|
with:
|
|
|
|
repository: "GoogleCloudPlatform/guest-agent"
|
2023-03-01 07:52:52 -05:00
|
|
|
ref: refs/tags/${{ steps.latest-release.outputs.latest }}
|
2022-08-09 10:33:37 -04:00
|
|
|
path: "guest-agent"
|
|
|
|
|
2023-01-18 04:15:58 -05:00
|
|
|
- name: Checkout Constellation
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2023-07-03 02:19:10 -04:00
|
|
|
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
|
2022-08-09 10:33:37 -04:00
|
|
|
with:
|
|
|
|
path: "constellation"
|
2022-12-19 09:21:28 -05:00
|
|
|
ref: ${{ !github.event.pull_request.head.repo.fork && github.head_ref || '' }}
|
2022-08-09 10:33:37 -04:00
|
|
|
|
|
|
|
- name: Docker meta
|
|
|
|
id: meta
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2023-07-03 02:19:10 -04:00
|
|
|
uses: docker/metadata-action@818d4b7b91585d195f67373fd9cb0332e31a7175 # v4.6.0
|
2022-08-09 10:33:37 -04:00
|
|
|
with:
|
|
|
|
images: |
|
|
|
|
${{ env.REGISTRY }}/edgelesssys/gcp-guest-agent
|
|
|
|
flavor: |
|
2023-03-01 07:52:52 -05:00
|
|
|
latest=false
|
2022-08-09 10:33:37 -04:00
|
|
|
tags: |
|
2023-03-10 10:44:42 -05:00
|
|
|
type=raw,value=${{ steps.latest-release-semver.outputs.latest }}
|
2023-03-01 07:52:52 -05:00
|
|
|
type=raw,value=${{ github.ref_name }},enable=${{ github.ref_name != 'main' }}
|
|
|
|
type=sha,value=${{ github.sha }}
|
|
|
|
type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
|
2022-09-14 09:14:26 -04:00
|
|
|
|
2022-08-09 10:33:37 -04:00
|
|
|
- name: Log in to the Container registry
|
|
|
|
id: docker-login
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2023-05-11 08:20:21 -04:00
|
|
|
uses: ./constellation/.github/actions/container_registry_login
|
2022-08-09 10:33:37 -04:00
|
|
|
with:
|
|
|
|
registry: ${{ env.REGISTRY }}
|
|
|
|
username: ${{ github.actor }}
|
|
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
|
|
|
|
- name: Prepare hardcoded configuration file
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2022-08-09 10:33:37 -04:00
|
|
|
run: |
|
|
|
|
cp "${GITHUB_WORKSPACE}/constellation/3rdparty/gcp-guest-agent/instance_configs.cfg" "${GITHUB_WORKSPACE}/guest-agent/"
|
|
|
|
|
|
|
|
- name: Build and push container image
|
2023-03-10 11:36:18 -05:00
|
|
|
if: steps.needs-build.outputs.out == 'true'
|
2022-08-09 10:33:37 -04:00
|
|
|
id: build
|
2023-06-20 07:39:32 -04:00
|
|
|
uses: docker/build-push-action@2eb1c1961a95fc15694676618e422e8ba1d63825 # v4.1.1
|
2022-08-09 10:33:37 -04:00
|
|
|
with:
|
|
|
|
context: ./guest-agent
|
|
|
|
file: ./constellation/3rdparty/gcp-guest-agent/Dockerfile
|
|
|
|
push: true
|
|
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
|
|
labels: ${{ steps.meta.outputs.labels }}
|