ci: publish portable containers after successful main deployment

This commit is contained in:
Simo committed 2026-09-07 23:02:18 +02:00
1 parent c4496e710b
commit f1571a1a62
3 files changed
+44 -4

No files matched your search

+22
View File
@@ -82,3 +82,25 @@ jobs:
env:
DEPLOY_BRANCH: ${{ gitea.ref_name }}
run: bash scripts/ci-deploy.sh
# Publish only after checks and the production deployment have succeeded.
# Serial execution also avoids two builds competing on the self-hosted runner.
publish-container:
needs: deploy
if: gitea.event_name == 'push' && (gitea.ref_name == 'main' || gitea.ref_name == 'master')
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Build, verify portability and publish
shell: bash
env:
REGISTRY_SERVER: ${{ gitea.server_url }}
REGISTRY_REPOSITORY: ${{ gitea.repository }}
REGISTRY_USER: ${{ secrets.CONTAINER_REGISTRY_USER }}
REGISTRY_TOKEN: ${{ secrets.CONTAINER_REGISTRY_TOKEN }}
run: bash scripts/publish-container.sh
+8 -4
View File
@@ -222,10 +222,14 @@ To publish from Gitea:
1. In the repository's Actions secrets, configure `CONTAINER_REGISTRY_USER` and
`CONTAINER_REGISTRY_TOKEN`. Use a Gitea access token with package read/write
permission belonging to an account allowed to publish under the repository owner.
2. Run **Publish portable container** manually on the commit/branch to distribute.
The workflow runs checks, builds from committed source only, and verifies the same
application image with two runtime avatar/badge configurations before pushing.
It does not deploy to production or move a `latest` tag.
2. Every push to `main` or `master` automatically builds and publishes the images
after the CI checks and production deployment succeed. Pull requests do not
publish images. The publication job builds from committed source only and checks
the same application image with two runtime configurations before pushing.
Missing registry secrets fail the publication job explicitly; they do not undo
an already successful production deployment. No `latest` tag is moved.
**Publish portable container** remains available for manual retries on the
commit/branch to distribute, without redeploying production.
3. The images are `<gitea-host>/<owner>/<repository-lowercase>:<full-commit>` and
`:<full-commit>-migrations`. Only the application image runs the website; the
migrations image is used temporarily for the matching database migrations.
+14
View File
@@ -39,3 +39,17 @@ it("builds the checked out source without fetching a moving remote branch", () =
);
expect(dockerfile).not.toMatch(/^RUN\s+git\s+(?:pull|fetch|clone)\b/m);
});
it("publishes commit images after successful main deployment and preserves manual retries", () => {
const publish = workflow.slice(workflow.indexOf("\n publish-container:"));
expect(publish).toContain("needs: deploy");
expect(publish).toContain("gitea.event_name == 'push'");
expect(publish).toContain("gitea.ref_name == 'main'");
expect(publish).toContain("gitea.ref_name == 'master'");
expect(publish).toContain("bash scripts/publish-container.sh");
expect(publish).toContain("secrets.CONTAINER_REGISTRY_USER");
expect(publish).toContain("secrets.CONTAINER_REGISTRY_TOKEN");
const manual = readFileSync(".gitea/workflows/container.yaml", "utf8");
expect(manual).toContain("workflow_dispatch:");
expect(manual).not.toMatch(/^ {2}push:/m);
});