forked from MostlyDevOps/wordsmith-web
-
Notifications
You must be signed in to change notification settings - Fork 1
103 lines (95 loc) · 2.95 KB
/
call-docker-build-promote.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
---
name: Build-Promote-GitOps
on:
push:
branches:
- main
paths-ignore:
- 'README.md'
- '.github/linters/**'
pull_request:
paths-ignore:
- 'README.md'
- '.github/linters/**'
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
jobs:
#### PULL REQUEST ####
docker-build-pr:
name: Call Build on PR
if: github.event_name == 'pull_request'
permissions:
contents: read
packages: write
pull-requests: write
uses: mostlydevops/actions/.github/workflows/reusable-docker-build.yaml@main
with:
# DON'T login to or push to Docker Hub
dockerhub-enable: false
ghcr-enable: true
push: true
platforms: linux/amd64,linux/arm64
image-names: |
ghcr.io/${{ github.repository }}
scan-pr:
name: CVE Scan
if: github.event_name == 'pull_request'
needs: docker-build-pr
permissions:
packages: read
uses: mostlydevops/actions/.github/workflows/reusable-trivy-scan-image.yaml@main
secrets:
registry-username: ${{ github.actor }}
registry-password: ${{ secrets.GITHUB_TOKEN }}
with:
image: 'ghcr.io/UffizziCloud/wordsmith-web:${{ needs.docker-build-pr.outputs.image-tag }}'
exit-code: 1
severity: HIGH,CRITICAL
ignore-unfixed: true
preview:
name: Preview
if: github.event_name == 'pull_request'
needs: docker-build-pr
uses: UffizziCloud/actions/.github/workflows/reusable-uffizzi.yaml@uffizzi
secrets:
github-token: ${{ secrets.GITOPS_WORDSMITH_K8S }}
with:
repo: UffizziCloud/wordsmith-k8s
environment-dir: preview-uffizzi
image: ghcr.io/${{ github.repository }}
tag: ${{ needs.docker-build-pr.outputs.image-tag }}
pr-number: ${{ github.event.number }}
#### MERGE TO MAIN ####
docker-build-merge:
name: Call Build on Push
if: github.event_name == 'push'
permissions:
contents: read
packages: write
pull-requests: write
uses: mostlydevops/actions/.github/workflows/reusable-docker-build.yaml@main
with:
dockerhub-enable: false
ghcr-enable: true
push: true
platforms: linux/amd64,linux/arm64
image-names: |
ghcr.io/${{ github.repository }}
ghcr.io/${{ github.repository }}-stable
tag-rules: |
type=raw,value={{date 'YYYYMMDD'}}-{{sha}},enable={{is_default_branch}},priority=300
type=ref,event=tag,priority=200
type=raw,value=latest,enable={{is_default_branch}},priority=100
gitops-pr:
name: Call GitOps PR
if: github.event_name == 'push'
needs: docker-build-merge
uses: mostlydevops/actions/.github/workflows/reusable-gitops-pr.yaml@main
secrets:
github-token: ${{ secrets.GITOPS_WORDSMITH_K8S }}
with:
repo: UffizziCloud/wordsmith-k8s
environment-dir: production
image: ghcr.io/${{ github.repository }}-stable
tag: ${{ needs.docker-build-merge.outputs.image-tag }}