feat(docker): prepare portable images with runtime hotel configuration
This commit is contained in:
1 parent
745d0b7247
commit
c4496e710b
28 files changed
+622
-104
No files matched your search
@@ -0,0 +1,30 @@
|
||||
#!/usr/bin/env bash
|
||||
set -Eeuo pipefail
|
||||
: "${REGISTRY_SERVER:?Missing Gitea server URL}"
|
||||
: "${REGISTRY_REPOSITORY:?Missing owner/repository}"
|
||||
: "${REGISTRY_USER:?Configure CONTAINER_REGISTRY_USER}"
|
||||
: "${REGISTRY_TOKEN:?Configure CONTAINER_REGISTRY_TOKEN with package write access}"
|
||||
sha="$(git rev-parse HEAD)"
|
||||
[[ "$sha" =~ ^[0-9a-f]{40}$ ]] || exit 1
|
||||
registry="${REGISTRY_SERVER#https://}"
|
||||
registry="${registry%/}"
|
||||
[[ "$REGISTRY_SERVER" = https://* && "$registry" != */* ]] || { echo "Registry must use HTTPS at the Gitea server root" >&2; exit 1; }
|
||||
repository="${REGISTRY_REPOSITORY,,}"
|
||||
[[ "$repository" =~ ^[a-z0-9._-]+/[a-z0-9._-]+$ ]] || exit 1
|
||||
image="$registry/$repository:$sha"
|
||||
# Isolate credentials from the self-hosted runner's normal Docker configuration.
|
||||
export DOCKER_CONFIG
|
||||
DOCKER_CONFIG="$(mktemp -d)"
|
||||
context="$(mktemp -d)"
|
||||
trap 'rm -rf -- "$DOCKER_CONFIG" "$context"' EXIT
|
||||
# Build only the committed source, never untracked files from a shared runner.
|
||||
git archive HEAD | tar -x -C "$context"
|
||||
printf '%s' "$REGISTRY_TOKEN" | docker login "$registry" --username "$REGISTRY_USER" --password-stdin
|
||||
unset REGISTRY_TOKEN
|
||||
docker build --network=host --build-arg NEXT_DEPLOYMENT_ID="$sha" -t "$image" "$context"
|
||||
docker build --network=host --target migrations -t "$image-migrations" "$context"
|
||||
node scripts/verify-portable-image.mjs "$image" "$sha"
|
||||
# Publish only after the same application image passed both runtime configurations.
|
||||
docker push "$image-migrations"
|
||||
docker push "$image"
|
||||
echo "Published application and migrations: $image"
|
||||
Reference in new issue
Block a user