From 24c01844d4edfef680f08c95fabf6254c0070060 Mon Sep 17 00:00:00 2001 From: Tejas <98106526+ToxicBiohazard@users.noreply.github.com> Date: Tue, 29 Sep 2026 16:38:35 +0530 Subject: [PATCH] ci: build images in this repository The publish job no longer calls another repository. Development and production still publish from the same workflow. Co-authored-by: Cursor --- .github/workflows/deploy.yaml | 79 ++++++++++++++++++++++++++++++----- 1 file changed, 69 insertions(+), 10 deletions(-) diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 8261e58..49a1481 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -11,7 +11,10 @@ on: permissions: id-token: write contents: read - packages: write + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.ref_type != 'tag' || contains(github.ref_name, '-rc') }} jobs: set-environment: @@ -20,20 +23,76 @@ jobs: outputs: role: ${{ steps.vars.outputs.role }} repository: ${{ steps.vars.outputs.repository }} + registry: ${{ steps.vars.outputs.registry }} steps: - id: vars run: | echo "role=${{ vars.AWS_GITHUB_ROLE }}" >> "$GITHUB_OUTPUT" echo "repository=${{ vars.ECR_REPOSITORY }}" >> "$GITHUB_OUTPUT" + echo "registry=${{ vars.ECR_REGISTRY }}" >> "$GITHUB_OUTPUT" build: needs: set-environment - uses: hackthebox/workflows/.github/workflows/build-docker-image.yml@main - with: - ecr_enabled: true - ecr_repository: ${{ needs.set-environment.outputs.repository }} - ecr_role_arn: ${{ needs.set-environment.outputs.role }} - environment_name: ${{ github.ref_type == 'tag' && !contains(github.ref_name, '-rc') && 'production' || 'development' }} - runner: ubuntu-latest - enable_dockerhub_login: false - secrets: inherit + runs-on: ubuntu-latest + steps: + - name: Checkout repo + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + fetch-depth: 0 + + - name: Determine image tag + id: config + run: | + set -euo pipefail + if [[ "${GITHUB_REF_TYPE}" == "tag" && "$GITHUB_REF_NAME" != *-rc* ]]; then + VERSION="${GITHUB_REF_NAME#v}" + IMAGE_TAG="$VERSION" + else + TIMESTAMP="$(date +%s)" + SHORT_SHA="$(git rev-parse HEAD | cut -c1-7)" + VERSION="$(git describe --tags --always)" + IMAGE_TAG="${TIMESTAMP}-${SHORT_SHA}" + fi + echo "image_tag=${IMAGE_TAG}" >> "$GITHUB_OUTPUT" + echo "version=${VERSION}" >> "$GITHUB_OUTPUT" + + - name: Read registry + id: registry + env: + ECR_REGISTRY: ${{ needs.set-environment.outputs.registry }} + run: | + set -euo pipefail + if [[ "$ECR_REGISTRY" =~ ^([0-9]+)\.dkr\.ecr\.([a-z0-9-]+)\.amazonaws\.com$ ]]; then + echo "account_id=${BASH_REMATCH[1]}" >> "$GITHUB_OUTPUT" + echo "region=${BASH_REMATCH[2]}" >> "$GITHUB_OUTPUT" + else + echo "::error::ECR_REGISTRY must be the registry host" + exit 1 + fi + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 + + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + with: + role-to-assume: ${{ needs.set-environment.outputs.role }} + aws-region: ${{ steps.registry.outputs.region }} + + - name: Login to Amazon ECR + id: login-ecr + uses: aws-actions/amazon-ecr-login@03f1aad4c6c7ffd436567f42f9384779290529bd # v2.1.7 + with: + registries: ${{ steps.registry.outputs.account_id }} + + - name: Build and push + uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 + with: + context: . + push: true + platforms: linux/amd64 + tags: ${{ steps.login-ecr.outputs.registry }}/${{ needs.set-environment.outputs.repository }}:${{ steps.config.outputs.image_tag }} + build-args: | + VERSION=${{ steps.config.outputs.version }} + cache-from: type=registry,ref=${{ steps.login-ecr.outputs.registry }}/${{ needs.set-environment.outputs.repository }}:buildcache + cache-to: type=registry,ref=${{ steps.login-ecr.outputs.registry }}/${{ needs.set-environment.outputs.repository }}:buildcache,mode=max