mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
148 lines
6.0 KiB
YAML
148 lines
6.0 KiB
YAML
name: Release Images
|
|
|
|
# Publishes ghcr.io/immich-app/yucca/<app>:v<version> for a release tag,
|
|
# independent of Deploy: nothing that cancels, coalesces, or fails a Deploy
|
|
# run can suppress these images.
|
|
on:
|
|
release:
|
|
types: [published]
|
|
# Manual heal for a release whose images are missing.
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: Release tag to publish images for (e.g. v0.38.0)
|
|
required: true
|
|
type: string
|
|
|
|
concurrency:
|
|
group: release-images-${{ github.event.release.tag_name || inputs.tag }}
|
|
cancel-in-progress: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
images:
|
|
name: Publish release images
|
|
runs-on: ubuntu-latest
|
|
# Covers the 60m wait bound plus a fully cold eight-app fallback with
|
|
# margin; the loop probes per app, so a rerun finishes any remainder.
|
|
timeout-minutes: 180
|
|
permissions:
|
|
actions: read
|
|
contents: read
|
|
packages: write
|
|
env:
|
|
IMAGE_PREFIX: ghcr.io/immich-app/yucca
|
|
TAG: ${{ github.event.release.tag_name || inputs.tag }}
|
|
steps:
|
|
- name: Checkout release tree
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
ref: refs/tags/${{ github.event.release.tag_name || inputs.tag }}
|
|
persist-credentials: false
|
|
|
|
# Peel to the commit in case the tag is annotated; sha- image tags name
|
|
# commits, never tag objects.
|
|
- name: Resolve the tagged commit
|
|
id: commit
|
|
run: echo "sha=$(git rev-parse "refs/tags/${TAG}^{commit}")" >> "$GITHUB_OUTPUT"
|
|
|
|
# Deploy's run for this commit is created as queued the moment the
|
|
# commit lands, and queue: max never coalesces it away; poll it to
|
|
# completion (any conclusion) so the probes below can retag its images
|
|
# digest-identically. The wait is an optimization, never a gate: after
|
|
# 60 minutes (a deep FIFO queue), or three polls with no run listed
|
|
# (runs aged out of retention), proceed and let the fallback build
|
|
# from the tag tree.
|
|
- name: Wait for the release commit's Deploy run
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
COMMIT: ${{ steps.commit.outputs.sha }}
|
|
run: |
|
|
runs="repos/immich-app/yucca/actions/workflows/deploy.yml/runs?head_sha=${COMMIT}&branch=main&per_page=1"
|
|
missing=0
|
|
polls=0
|
|
while :; do
|
|
status=$(gh api "$runs" --jq '.workflow_runs[0].status' || true)
|
|
[ "$status" = "completed" ] && break
|
|
if [ -z "$status" ]; then
|
|
missing=$((missing + 1))
|
|
[ "$missing" -ge 3 ] && { echo "no Deploy run listed for ${COMMIT}; proceeding"; break; }
|
|
fi
|
|
polls=$((polls + 1))
|
|
[ "$polls" -ge 60 ] && { echo "Deploy run still ${status} after 60m; proceeding to the fallback"; break; }
|
|
echo "Deploy run for ${COMMIT} is ${status:-not listed yet}; polling again in 60s"
|
|
sleep 60
|
|
done
|
|
|
|
- name: Set up Buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
# The runner injects ACTIONS_RUNTIME_TOKEN/ACTIONS_RESULTS_URL into
|
|
# action steps only, and buildx invoked from run: silently drops
|
|
# type=gha cache without them.
|
|
- name: Expose GitHub runtime for buildx gha cache
|
|
uses: crazy-max/ghaction-github-runtime@04d248b84655b509d8c44dc1d6f990c879747487 # v4.0.0
|
|
|
|
# The roster is the Deploy build matrix read from this tag's tree, so
|
|
# the two cannot drift; an app newer than the tag has no Dockerfile
|
|
# here and nothing to publish. When sha-<commit> exists it is retagged
|
|
# (--prefer-index=false keeps the single-platform manifest format), so
|
|
# the v-tag digest equals the digest staging ran; when it does not,
|
|
# the fallback builds the same tree content under a new digest.
|
|
- name: Publish release images
|
|
env:
|
|
COMMIT: ${{ steps.commit.outputs.sha }}
|
|
run: |
|
|
apps="$(yq '.jobs.build.strategy.matrix.app[] | .name + " " + .dockerfile' .github/workflows/deploy.yml)"
|
|
[ -n "$apps" ] || { echo "::error::no apps parsed from the build matrix"; exit 1; }
|
|
# 0 = present, 1 = absent; any probe failure that is neither must
|
|
# not lead to a publish.
|
|
probe() {
|
|
local err
|
|
if err=$(docker manifest inspect "$1" 2>&1 >/dev/null); then
|
|
return 0
|
|
fi
|
|
case "$err" in
|
|
*"manifest unknown"* | *"no such manifest"* | *"not found"*) return 1 ;;
|
|
esac
|
|
echo "::error::probe for $1 failed: $err"
|
|
exit 1
|
|
}
|
|
failed=""
|
|
while read -r app df; do
|
|
if [ ! -f "$df" ]; then
|
|
echo "::error::$app dockerfile $df missing in $TAG"
|
|
failed="$failed $app"
|
|
continue
|
|
fi
|
|
vref="${IMAGE_PREFIX}/${app}:${TAG}"
|
|
if probe "$vref"; then
|
|
echo "$vref present"
|
|
continue
|
|
fi
|
|
sha_ref="${IMAGE_PREFIX}/${app}:sha-${COMMIT}"
|
|
if probe "$sha_ref"; then
|
|
echo "$vref missing; retagging $sha_ref"
|
|
docker buildx imagetools create --prefer-index=false \
|
|
-t "$vref" "$sha_ref" || failed="$failed $app"
|
|
continue
|
|
fi
|
|
echo "$vref missing and $sha_ref absent; building from the tag tree"
|
|
docker buildx build --push \
|
|
--file "$df" \
|
|
--tag "$vref" \
|
|
--cache-from "type=gha,scope=${app}" \
|
|
--cache-to "type=gha,mode=max,scope=${app}" \
|
|
. || failed="$failed $app"
|
|
done < <(printf '%s\n' "$apps")
|
|
[ -z "$failed" ] || { echo "::error::publish failed for:$failed"; exit 1; }
|