From 2e49a8eb31c7a4f0d49aa0757c908fdd40fc7c25 Mon Sep 17 00:00:00 2001 From: mrambossek Date: Wed, 26 Aug 2026 13:02:33 +0200 Subject: [PATCH] fix workflow --- .gitea/workflows/build.yaml | 125 +++++++++++++++++++++++++++--------- 1 file changed, 93 insertions(+), 32 deletions(-) diff --git a/.gitea/workflows/build.yaml b/.gitea/workflows/build.yaml index 291d10b..5e12181 100644 --- a/.gitea/workflows/build.yaml +++ b/.gitea/workflows/build.yaml @@ -1,36 +1,38 @@ -name: Build fdroidserver-ipfs image +# ci-images/fdroidserver-ipfs/.gitea/workflows/build.yaml +# +# Daily check, build ONLY when the upstream base or the Dockerfile changed. +# See the flutter-node variant for the full explanation - identical logic, +# one upstream base instead of two. + +name: build -# Triggers: -# - push to main → immediate rebuild (any change in the repo) -# - weekly cron → picks up upstream :master refreshes in -# docker-executable-fdroidserver without a -# source change here -# - manual dispatch → on-demand on: + schedule: + - cron: "0 4 * * *" push: branches: [main] - schedule: - # Sun 04:00 UTC. - - cron: "0 4 * * 0" workflow_dispatch: + inputs: + force: + description: "Build even if no upstream change was detected" + type: boolean + default: false + +env: + IMAGE: ${{ vars.REGISTRY_HOST }}/ci-images/fdroidserver-ipfs + FDROIDSERVER_IMAGE: registry.gitlab.com/fdroid/docker-executable-fdroidserver:master jobs: - build: - # Skip the job entirely (no runner provisioning) when the registry host - # isn't configured — shows as "skipped" in the UI rather than burning - # minutes on a build that can't be pushed. Secrets can't be referenced - # in job-level if:, so REGISTRY_TOKEN is still checked below. - if: vars.REGISTRY_HOST != '' + check: runs-on: ubuntu-docker - permissions: - packages: write + outputs: + changed: ${{ steps.cmp.outputs.changed }} + hash: ${{ steps.hash.outputs.hash }} + base: ${{ steps.up.outputs.base }} + date: ${{ steps.date.outputs.date }} steps: - name: Validate registry token - run: | - if [ -z "${{ secrets.REGISTRY_TOKEN }}" ]; then - echo "::error::Missing required config: secrets.REGISTRY_TOKEN" - exit 1 - fi + run: test -n "${{ secrets.REGISTRY_TOKEN }}" || { echo "REGISTRY_TOKEN missing"; exit 1; } - name: Checkout uses: actions/checkout@v4 @@ -38,15 +40,69 @@ jobs: - name: Set up Buildx uses: docker/setup-buildx-action@v3 + - name: Log in to Gitea registry + uses: docker/login-action@v3 + with: + registry: ${{ vars.REGISTRY_HOST }} + username: ${{ github.actor }} + password: ${{ secrets.REGISTRY_TOKEN }} + + - name: Resolve upstream digest + id: up + run: | + set -euo pipefail + b=$(docker buildx imagetools inspect "$FDROIDSERVER_IMAGE" --format '{{.Manifest.Digest}}') + echo "base=$b" >> "$GITHUB_OUTPUT" + echo "base: $b" + + - name: Compute input hash + id: hash + run: | + set -euo pipefail + h=$(printf '%s\n' \ + "${{ steps.up.outputs.base }}" \ + "$(sha256sum Dockerfile | cut -d' ' -f1)" \ + | sha256sum | cut -c1-12) + echo "hash=$h" >> "$GITHUB_OUTPUT" + echo "input hash: $h" + + - name: Compare against what is already published + id: cmp + run: | + set -euo pipefail + if [ "${{ github.event_name }}" != "schedule" ] || [ "${{ inputs.force }}" = "true" ]; then + echo "changed=true" >> "$GITHUB_OUTPUT" + echo "non-scheduled or forced run - building" + exit 0 + fi + if docker buildx imagetools inspect "$IMAGE:src-${{ steps.hash.outputs.hash }}" >/dev/null 2>&1; then + echo "changed=false" >> "$GITHUB_OUTPUT" + echo "no change since last build - skipping" + else + echo "changed=true" >> "$GITHUB_OUTPUT" + echo "upstream or Dockerfile changed - building" + fi + - name: Compute date tag id: date run: echo "date=$(date -u +%Y%m%d)" >> "$GITHUB_OUTPUT" + build: + needs: check + if: needs.check.outputs.changed == 'true' + runs-on: ubuntu-docker + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Set up Buildx + uses: docker/setup-buildx-action@v3 + - name: Log in to Gitea registry uses: docker/login-action@v3 with: registry: ${{ vars.REGISTRY_HOST }} - username: ${{ gitea.actor }} + username: ${{ github.actor }} password: ${{ secrets.REGISTRY_TOKEN }} - name: Build and push @@ -54,13 +110,18 @@ jobs: with: context: . push: true - # Two tags: - # :stable — moving, what callers pull by default - # :YYYYMMDD — immutable, for pinning / rollback - tags: | - ${{ vars.REGISTRY_HOST }}/ci-images/fdroidserver-ipfs:stable - ${{ vars.REGISTRY_HOST }}/ci-images/fdroidserver-ipfs:${{ steps.date.outputs.date }} + pull: true + provenance: false + cache-from: type=registry,ref=${{ env.IMAGE }}:stable + cache-to: type=inline build-args: | IMAGE_SOURCE=https://${{ vars.REGISTRY_HOST }}/ci-images/fdroidserver-ipfs - cache-from: type=registry,ref=${{ vars.REGISTRY_HOST }}/ci-images/fdroidserver-ipfs:stable - cache-to: type=inline + FDROIDSERVER_IMAGE=${{ env.FDROIDSERVER_IMAGE }}@${{ needs.check.outputs.base }} + labels: | + org.opencontainers.image.base.name=${{ env.FDROIDSERVER_IMAGE }} + org.opencontainers.image.base.digest=${{ needs.check.outputs.base }} + org.opencontainers.image.revision=${{ github.sha }} + tags: | + ${{ env.IMAGE }}:stable + ${{ env.IMAGE }}:${{ needs.check.outputs.date }} + ${{ env.IMAGE }}:src-${{ needs.check.outputs.hash }}