Add CI and manual image publishing workflows
CI / Backend tests (push) Successful in 12m54s
CI / Frontend build & lint (push) Failing after 4m59s

- .gitea/workflows/ci.yml: on every push/PR, run Django checks + the full
  backend suite against MariaDB/Redis services and the frontend
  lint/type-check/build. Runs on the nitro-ci runner (ubuntu-latest).
- .gitea/workflows/publish.yml: manual dispatch; multi-arch build+push of
  both images as :latest and :<short-sha> with GIT_HASH baked in.
- push_*.sh: non-interactive registry login for CI (REGISTRY_USER/
  REGISTRY_TOKEN) and a PLATFORMS override.
This commit is contained in:
2026-09-22 22:32:37 -05:00
parent e2697c0a78
commit d9c1e9e521
4 changed files with 181 additions and 4 deletions
+51
View File
@@ -0,0 +1,51 @@
# J621 image publishing — manual workflow.
#
# Builds the backend (gunicorn + whitenoise, ffmpeg) and frontend (static
# nginx) images for linux/amd64 + linux/arm64 and pushes them to the Gitea
# registry as :latest and :<short-sha>, with the commit baked in as GIT_HASH.
#
# Run it from the Actions tab ("Run workflow"), or:
# curl -X POST .../api/v1/repos/JakeBreath/J621/actions/workflows/publish.yml/dispatches \
# -d '{"ref":"main"}'
#
# Registry login uses the automatic GITHUB_TOKEN (the repo needs package write
# access for the actor); no extra secrets are required.
name: Publish images
on:
workflow_dispatch:
inputs:
platforms:
description: Build platforms (comma separated)
required: false
default: linux/amd64,linux/arm64
concurrency:
group: publish
cancel-in-progress: false
jobs:
publish:
name: Build & push images
runs-on: ubuntu-latest
env:
REGISTRY_USER: ${{ github.actor }}
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Register binfmt (multi-arch builds)
run: docker run --privileged --rm tonistiigi/binfmt --install all
- name: Build & push both images
run: |
set -euo pipefail
SHA="$(git rev-parse --short HEAD)"
echo "Publishing $SHA for $PLATFORMS"
# Both scripts honour REGISTRY_USER/REGISTRY_TOKEN (see deploy/push_*.sh).
PLATFORMS="$PLATFORMS" ./deploy/push_frontend.sh "$SHA"
PLATFORMS="$PLATFORMS" ./deploy/push_backend.sh "$SHA"