73 lines
2.0 KiB
YAML
73 lines
2.0 KiB
YAML
name: push
|
|
run-name: Push action runner container to registry
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- master
|
|
paths:
|
|
- "Dockerfile"
|
|
- "gitea-ca.pem"
|
|
- ".gitea/workflows/**"
|
|
|
|
env:
|
|
REGISTRY: 192.168.1.33
|
|
IMAGE_NAME: gitea-masters/runners
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Set up QEMU
|
|
uses: actions/setup-qemu-action@v3
|
|
|
|
- name: Fetch registry TLS certificate
|
|
run: |
|
|
mkdir -p "$RUNNER_TEMP/certs"
|
|
for host in 192.168.1.33 192.168.1.90; do
|
|
openssl s_client -connect "$host:443" -servername "$host" </dev/null 2>/dev/null \
|
|
| openssl x509 -outform PEM > "$RUNNER_TEMP/certs/$host.crt"
|
|
done
|
|
cat "$RUNNER_TEMP/certs/"*.crt
|
|
|
|
- name: Build custom buildkit image with trusted CA
|
|
run: |
|
|
cat > "$RUNNER_TEMP/Dockerfile.buildkit" <<'EOF'
|
|
FROM moby/buildkit:buildx-stable-1
|
|
COPY certs/*.crt /usr/local/share/ca-certificates/
|
|
RUN cat /usr/local/share/ca-certificates/*.crt >> /etc/ssl/certs/ca-certificates.crt
|
|
EOF
|
|
docker build -t local/buildkit-with-ca:latest \
|
|
-f "$RUNNER_TEMP/Dockerfile.buildkit" "$RUNNER_TEMP"
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: actions/setup-buildx-action@v3
|
|
with:
|
|
driver: docker-container
|
|
driver-opts: |
|
|
image=local/buildkit-with-ca:latest
|
|
|
|
- name: Login to registry
|
|
uses: actions/login-action@v3
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ gitea.actor }}
|
|
password: ${{ secrets.OCI_TOKEN }}
|
|
|
|
- name: docker
|
|
uses: actions/build-push-action@v6
|
|
with:
|
|
context: .
|
|
file: Dockerfile
|
|
platforms: |
|
|
linux/amd64
|
|
linux/arm64/v8
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ gitea.ref_name }}
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
|
|
|