Merging a pull request into main is now the whole release. A Gitea Actions workflow derives the CalVer tag, builds the image and pushes it with :latest, so nothing is built locally any more. That made image/push/release redundant, and with them the .release-tag state file and the main-branch guard — the workflow only runs on main, which is protected, so the guard had nothing left to catch. The digest verification went too: it guarded a `make -j` race between image and push that cannot happen in a single CI job. seed, icons and vendor ran a few times a year and are written out in the README instead. Makefile: 151 lines to 71. Docs referenced the removed targets in sixteen places, including a CONTRIBUTING note claiming the branch check "has to be local".
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
name: release
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
# ponytail: only because Traefik still serves its default self-signed cert for
|
||||
# git.kessinen.com. Remove once the LE-DNS01-cloudflare runbook has been run.
|
||||
env:
|
||||
GIT_SSL_NO_VERIFY: "true"
|
||||
REGISTRY: git.kessinen.com
|
||||
IMAGE: git.kessinen.com/kessinen/foodster
|
||||
|
||||
jobs:
|
||||
image:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# Full history and tags: the release number is derived by counting the
|
||||
# tags already cut today.
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
# The job container is node:22-bookworm and has no docker client. The
|
||||
# static binary is one file; installing docker.io would pull a daemon
|
||||
# that is never used, since the build runs against the host's.
|
||||
- name: Install the docker client
|
||||
run: |
|
||||
curl -fsSL https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \
|
||||
| tar xz --strip-components=1 -C /usr/local/bin docker/docker
|
||||
docker version --format '{{.Client.Version}}'
|
||||
|
||||
- name: Work out the release tag
|
||||
id: rel
|
||||
run: |
|
||||
day=$(date +%Y%m%d)
|
||||
tag="v$day-$(( $(git tag -l "v$day-*" | wc -l) + 1 ))"
|
||||
echo "tag=$tag" >> "$GITHUB_OUTPUT"
|
||||
echo "==> $tag"
|
||||
|
||||
- name: Tag the commit
|
||||
run: |
|
||||
git tag "${{ steps.rel.outputs.tag }}"
|
||||
git push origin "${{ steps.rel.outputs.tag }}"
|
||||
|
||||
- name: Log in to the registry
|
||||
run: |
|
||||
echo "${{ secrets.GITEA_TOKEN }}" \
|
||||
| docker login "$REGISTRY" -u "${{ gitea.actor }}" --password-stdin
|
||||
|
||||
- name: Build and push
|
||||
run: |
|
||||
tag="${{ steps.rel.outputs.tag }}"
|
||||
docker build --platform linux/amd64 --build-arg VERSION="$tag" \
|
||||
-f Containerfile \
|
||||
-t "$IMAGE:$tag" -t "$IMAGE:latest" .
|
||||
docker push "$IMAGE:$tag"
|
||||
docker push "$IMAGE:latest"
|
||||
echo "pushed $IMAGE:$tag and :latest - pull it in dockge when ready"
|
||||
Reference in New Issue
Block a user