- ci.yml: connect to the test MariaDB as root so Django creates the test database itself (no client install/grant step), and drop actions/cache (cache: pip/npm): Gitea's cache service hangs the job on restore/save. - publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other repos) and fall back to the automatic Actions token. - AGENTS.md: note the CI layout, the runner labels and the cache caveat.
54 lines
1.8 KiB
YAML
54 lines
1.8 KiB
YAML
# J621 image publishing — manual workflow.
|
|
#
|
|
# Builds the backend (gunicorn + whitenoise, ffmpeg) and frontend (static
|
|
# nginx) images for linux/amd64 + linux/arm64 and pushes them to the Gitea
|
|
# registry as :latest and :<short-sha>, with the commit baked in as GIT_HASH.
|
|
#
|
|
# Run it from the Actions tab ("Run workflow"), or:
|
|
# curl -X POST .../api/v1/repos/JakeBreath/J621/actions/workflows/publish.yml/dispatches \
|
|
# -d '{"ref":"main"}'
|
|
#
|
|
# Registry login uses the automatic GITHUB_TOKEN (the repo needs package write
|
|
# access for the actor); no extra secrets are required.
|
|
|
|
name: Publish images
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
platforms:
|
|
description: Build platforms (comma separated)
|
|
required: false
|
|
default: linux/amd64,linux/arm64
|
|
|
|
concurrency:
|
|
group: publish
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
publish:
|
|
name: Build & push images
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
# Prefer dedicated registry secrets (as on other repos); fall back to
|
|
# the automatic Actions token.
|
|
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
|
|
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Register binfmt (multi-arch builds)
|
|
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
|
|
|
- name: Build & push both images
|
|
run: |
|
|
set -euo pipefail
|
|
SHA="$(git rev-parse --short HEAD)"
|
|
echo "Publishing $SHA for $PLATFORMS"
|
|
# Both scripts honour REGISTRY_USER/REGISTRY_TOKEN (see deploy/push_*.sh).
|
|
PLATFORMS="$PLATFORMS" ./deploy/push_frontend.sh "$SHA"
|
|
PLATFORMS="$PLATFORMS" ./deploy/push_backend.sh "$SHA"
|