forked from openclaw/openclaw
-
Notifications
You must be signed in to change notification settings - Fork 0
140 lines (131 loc) 路 4.5 KB
/
Copy pathdocker-image-refresh.yml
File metadata and controls
140 lines (131 loc) 路 4.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
name: Docker Image Refresh
on:
workflow_dispatch:
inputs:
channel:
description: Release channel to rebuild
required: false
default: both
type: choice
options:
- stable
- extended-stable
- both
dry_run:
description: Resolve and summarize without publishing
required: false
default: false
type: boolean
schedule:
- cron: "17 3 * * 1"
permissions:
contents: read
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
jobs:
plan:
runs-on: ubuntu-24.04
permissions:
contents: read
outputs:
dry_run: ${{ steps.plan.outputs.dry_run }}
image_tag_suffix: ${{ steps.plan.outputs.image_tag_suffix }}
matrix: ${{ steps.plan.outputs.matrix }}
steps:
- name: Require a main-branch run
env:
WORKFLOW_REF: ${{ github.ref }}
run: |
set -euo pipefail
if [[ "${WORKFLOW_REF}" != "refs/heads/main" ]]; then
echo "::error::Docker image refresh must run from main; got ${WORKFLOW_REF}."
exit 1
fi
- name: Checkout trusted refresh tooling
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false
- name: Resolve refresh plan
id: plan
shell: bash
env:
CHANNEL: ${{ github.event_name == 'schedule' && 'both' || inputs.channel }}
DRY_RUN: ${{ github.event_name == 'schedule' && 'false' || inputs.dry_run }}
run: |
set -euo pipefail
current="$(git tag --list 'v*' | node scripts/lib/docker-release-policy.mjs --current)"
stable_tag="$(jq -er '.stable.tag' <<< "${current}")"
extended_stable_tag="$(jq -er '.extendedStable.tag' <<< "${current}")"
stable_sha="$(git rev-parse "refs/tags/${stable_tag}^{commit}")"
extended_stable_sha="$(git rev-parse "refs/tags/${extended_stable_tag}^{commit}")"
suffix="-r$(date -u +%Y%m%d)"
stable_entry="$(
jq -cn \
--arg channel stable \
--arg tag "${stable_tag}" \
--arg release_sha "${stable_sha}" \
'{channel: $channel, tag: $tag, release_sha: $release_sha}'
)"
extended_stable_entry="$(
jq -cn \
--arg channel extended-stable \
--arg tag "${extended_stable_tag}" \
--arg release_sha "${extended_stable_sha}" \
'{channel: $channel, tag: $tag, release_sha: $release_sha}'
)"
case "${CHANNEL}" in
stable)
matrix="$(jq -cn --argjson stable "${stable_entry}" '[$stable]')"
;;
extended-stable)
matrix="$(jq -cn --argjson extended "${extended_stable_entry}" '[$extended]')"
;;
both)
matrix="$(
jq -cn \
--argjson stable "${stable_entry}" \
--argjson extended "${extended_stable_entry}" \
'[$stable, $extended]'
)"
;;
*)
echo "::error::Unsupported Docker refresh channel: ${CHANNEL}"
exit 1
;;
esac
{
echo "dry_run=${DRY_RUN}"
echo "image_tag_suffix=${suffix}"
echo "matrix=${matrix}"
} >> "${GITHUB_OUTPUT}"
{
echo "## Docker image refresh plan"
echo "- Stable: ${stable_tag} (${stable_sha})"
echo "- Extended stable: ${extended_stable_tag} (${extended_stable_sha})"
echo "- Image tag suffix: ${suffix}"
echo "- Selected channel: ${CHANNEL}"
echo "- Dry run: ${DRY_RUN}"
} >> "${GITHUB_STEP_SUMMARY}"
publish:
name: Refresh ${{ matrix.channel }} Docker images
needs: plan
if: needs.plan.outputs.dry_run != 'true'
strategy:
fail-fast: false
matrix:
include: ${{ fromJSON(needs.plan.outputs.matrix) }}
uses: ./.github/workflows/docker-release.yml
with:
tag: ${{ matrix.tag }}
release_sha: ${{ matrix.release_sha }}
image_tag_suffix: ${{ needs.plan.outputs.image_tag_suffix }}
secrets:
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
permissions:
actions: read
attestations: read
contents: read
packages: write