# J621 image publishing — manual workflow. # # Builds the backend (gunicorn + whitenoise, ffmpeg) and frontend (static # nginx) images for linux/amd64 + linux/arm64 and pushes them to the Gitea # registry as :latest and :, with the commit baked in as GIT_HASH. # # Run it from the Actions tab ("Run workflow"), or: # curl -X POST .../api/v1/repos/JakeBreath/J621/actions/workflows/publish.yml/dispatches \ # -d '{"ref":"main"}' # # Registry login uses the automatic GITHUB_TOKEN (the repo needs package write # access for the actor); no extra secrets are required. name: Publish images on: workflow_dispatch: inputs: platforms: description: Build platforms (comma separated) required: false default: linux/amd64,linux/arm64 concurrency: group: publish cancel-in-progress: false jobs: publish: name: Build & push images runs-on: ubuntu-latest env: REGISTRY_USER: ${{ github.actor }} REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }} PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }} steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Register binfmt (multi-arch builds) run: docker run --privileged --rm tonistiigi/binfmt --install all - name: Build & push both images run: | set -euo pipefail SHA="$(git rev-parse --short HEAD)" echo "Publishing $SHA for $PLATFORMS" # Both scripts honour REGISTRY_USER/REGISTRY_TOKEN (see deploy/push_*.sh). PLATFORMS="$PLATFORMS" ./deploy/push_frontend.sh "$SHA" PLATFORMS="$PLATFORMS" ./deploy/push_backend.sh "$SHA"