name: Build Docker Image on: workflow_dispatch: inputs: release: description: Publish release aliases and redeploy production (false runs a cache-only build, then publishes a canary) type: boolean default: false push: branches: - main tags: - "v*" concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true env: GHCR_IMAGE: ghcr.io/${{ github.repository }} DOCKER_IMAGE: docker.io/amruthpillai/reactive-resume FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true jobs: mode: runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }} outputs: nightly: ${{ steps.mode.outputs.nightly }} release: ${{ steps.mode.outputs.release }} canary: ${{ steps.mode.outputs.canary }} steps: - name: Determine publishing mode id: mode env: EVENT_NAME: ${{ github.event_name }} GIT_REF: ${{ github.ref }} RELEASE: ${{ inputs.release }} run: | if [[ "$EVENT_NAME" == "push" && "$GIT_REF" == "refs/heads/main" ]]; then echo "nightly=true" >> "$GITHUB_OUTPUT" echo "release=false" >> "$GITHUB_OUTPUT" echo "canary=false" >> "$GITHUB_OUTPUT" elif [[ "$EVENT_NAME" == "workflow_dispatch" && "$RELEASE" != "true" ]]; then echo "nightly=false" >> "$GITHUB_OUTPUT" echo "release=false" >> "$GITHUB_OUTPUT" echo "canary=true" >> "$GITHUB_OUTPUT" else echo "nightly=false" >> "$GITHUB_OUTPUT" echo "release=true" >> "$GITHUB_OUTPUT" echo "canary=false" >> "$GITHUB_OUTPUT" fi build: needs: mode strategy: fail-fast: false matrix: include: - platform: linux/amd64 runner: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404' || 'ubuntu-latest' }} arch: amd64 - platform: linux/arm64 runner: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404-arm' || 'ubuntu-24.04-arm' }} arch: arm64 runs-on: ${{ matrix.runner }} timeout-minutes: 30 permissions: contents: read packages: write id-token: write attestations: write steps: - name: Checkout Repository if: ${{ vars.USE_BLACKSMITH != 'true' }} uses: actions/checkout@v6 - name: Checkout Repository (Blacksmith) if: ${{ vars.USE_BLACKSMITH == 'true' }} uses: useblacksmith/checkout@v1 - name: Setup Docker Buildx if: ${{ vars.USE_BLACKSMITH != 'true' }} uses: docker/setup-buildx-action@v4 # Persists BuildKit layers and the Dockerfile's pnpm cache mounts between runs, one cache per architecture. - name: Setup Docker Builder (Blacksmith) if: ${{ vars.USE_BLACKSMITH == 'true' }} uses: useblacksmith/setup-docker-builder@v2 with: cache-key: Dockerfile-${{ matrix.arch }} - ®istries name: Determine registries id: registries env: DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }} DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }} run: | set -euo pipefail dockerhub=false ghcr_image="${GHCR_IMAGE,,}" docker_image="${DOCKER_IMAGE,,}" images="$ghcr_image" if [[ -n "$DOCKER_USERNAME" && -n "$DOCKER_PASSWORD" ]]; then dockerhub=true images="${images}"$'\n'"$docker_image" fi { echo "ghcr_image=$ghcr_image" echo "docker_image=$docker_image" echo "images<> "$GITHUB_OUTPUT" - name: Login to Docker Hub if: ${{ steps.registries.outputs.dockerhub == 'true' }} uses: docker/login-action@v4 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_PASSWORD }} - name: Login to GitHub Container Registry uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v6 with: images: ${{ steps.registries.outputs.images }} tags: | type=sha,prefix=sha-,suffix=-${{ matrix.arch }} - name: Cache-only smoke build if: ${{ needs.mode.outputs.canary == 'true' && vars.USE_BLACKSMITH != 'true' }} uses: docker/build-push-action@v7 with: &cache-only-build context: . platforms: ${{ matrix.platform }} outputs: type=cacheonly - name: Cache-only smoke build (Blacksmith) if: ${{ needs.mode.outputs.canary == 'true' && vars.USE_BLACKSMITH == 'true' }} uses: useblacksmith/build-push-action@v2 with: *cache-only-build - name: Build and Push by Digest id: build if: ${{ vars.USE_BLACKSMITH != 'true' }} uses: docker/build-push-action@v7 with: &build-push context: . sbom: true push: true provenance: mode=max platforms: ${{ matrix.platform }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} annotations: ${{ steps.meta.outputs.annotations }} - name: Build and Push by Digest (Blacksmith) id: build-blacksmith if: ${{ vars.USE_BLACKSMITH == 'true' }} uses: useblacksmith/build-push-action@v2 with: *build-push - name: Export digest run: | mkdir -p /tmp/digests digest="${{ steps.build.outputs.digest || steps.build-blacksmith.outputs.digest }}" touch "/tmp/digests/${digest#sha256:}" - name: Upload digest uses: actions/upload-artifact@v7 with: name: digests-${{ matrix.arch }} path: /tmp/digests/* if-no-files-found: error retention-days: 1 merge: needs: - mode - build timeout-minutes: 30 runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }} env: DEPLOY: ${{ secrets.SSH_KEY != '' && secrets.SSH_HOST != '' && secrets.SSH_USER != '' }} PURGE_CLOUDFLARE: ${{ secrets.CLOUDFLARE_ZONE_ID != '' && secrets.CLOUDFLARE_API_TOKEN != '' }} permissions: contents: read packages: write id-token: write attestations: write steps: - name: Checkout Repository if: ${{ vars.USE_BLACKSMITH != 'true' }} uses: actions/checkout@v6 with: &checkout-package-json sparse-checkout: package.json sparse-checkout-cone-mode: false - name: Checkout Repository (Blacksmith) if: ${{ vars.USE_BLACKSMITH == 'true' }} uses: useblacksmith/checkout@v1 with: *checkout-package-json - name: Get version from package.json id: version run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT" - name: Download digests uses: actions/download-artifact@v8 with: path: /tmp/digests pattern: digests-* merge-multiple: true - name: Setup Docker Buildx uses: docker/setup-buildx-action@v4 - *registries - name: Login to Docker Hub if: ${{ steps.registries.outputs.dockerhub == 'true' }} uses: docker/login-action@v4 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_PASSWORD }} - name: Login to GitHub Container Registry uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Parse version components id: semver run: | VERSION="${{ steps.version.outputs.version }}" MAJOR=$(echo "$VERSION" | cut -d. -f1) MINOR=$(echo "$VERSION" | cut -d. -f2) echo "major=$MAJOR" >> "$GITHUB_OUTPUT" echo "minor=$MINOR" >> "$GITHUB_OUTPUT" - name: Extract metadata for Docker id: meta uses: docker/metadata-action@v6 with: images: ${{ steps.registries.outputs.images }} tags: | type=sha,prefix=sha- type=raw,value=canary-${{ github.run_id }}-${{ github.run_attempt }},enable=${{ needs.mode.outputs.canary == 'true' }} type=raw,value=nightly,enable=${{ needs.mode.outputs.nightly == 'true' }} type=raw,value=nightly-{{date 'YYYYMMDDHHmmss' tz='UTC'}},enable=${{ needs.mode.outputs.nightly == 'true' }} type=raw,value=latest,enable=${{ needs.mode.outputs.release == 'true' }} type=raw,value=v${{ steps.version.outputs.version }},enable=${{ needs.mode.outputs.release == 'true' }} type=raw,value=v${{ steps.semver.outputs.major }}.${{ steps.semver.outputs.minor }},enable=${{ needs.mode.outputs.release == 'true' }} type=raw,value=v${{ steps.semver.outputs.major }},enable=${{ needs.mode.outputs.release == 'true' }} - name: Create manifest list and push id: manifest working-directory: /tmp/digests run: | set -euo pipefail if [[ "${{ needs.mode.outputs.nightly }}" == "true" ]]; then FINAL_TAG="nightly" elif [[ "${{ needs.mode.outputs.canary }}" == "true" ]]; then FINAL_TAG="canary-${{ github.run_id }}-${{ github.run_attempt }}" else FINAL_TAG="v${{ steps.version.outputs.version }}" fi docker buildx imagetools create \ $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ --annotation "index:org.opencontainers.image.licenses=MIT" \ --annotation "index:org.opencontainers.image.title=Reactive Resume" \ --annotation "index:org.opencontainers.image.description=A free and open-source resume builder." \ --annotation "index:org.opencontainers.image.vendor=Amruth Pillai" \ --annotation "index:org.opencontainers.image.url=https://rxresu.me" \ --annotation "index:org.opencontainers.image.documentation=https://docs.rxresu.me" \ --annotation "index:org.opencontainers.image.source=https://github.com/${{ github.repository }}" \ --annotation "index:org.opencontainers.image.version=${{ steps.version.outputs.version }}" \ $(printf '${{ steps.registries.outputs.ghcr_image }}@sha256:%s ' *) # Get the digest of the multi-arch manifest GHCR_DIGEST=$(docker buildx imagetools inspect ${{ steps.registries.outputs.ghcr_image }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"') echo "final_tag=$FINAL_TAG" >> "$GITHUB_OUTPUT" echo "ghcr_digest=$GHCR_DIGEST" >> "$GITHUB_OUTPUT" if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then DOCKER_DIGEST=$(docker buildx imagetools inspect ${{ steps.registries.outputs.docker_image }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"') echo "docker_digest=$DOCKER_DIGEST" >> "$GITHUB_OUTPUT" fi - name: Install Cosign uses: sigstore/cosign-installer@v3 - name: Sign images with Cosign run: | # Sign GHCR image cosign sign --yes ${{ steps.registries.outputs.ghcr_image }}@${{ steps.manifest.outputs.ghcr_digest }} if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then # Sign Docker Hub image cosign sign --yes ${{ steps.registries.outputs.docker_image }}@${{ steps.manifest.outputs.docker_digest }} fi - name: Inspect image run: | docker buildx imagetools inspect ${{ steps.registries.outputs.ghcr_image }}:${{ steps.manifest.outputs.final_tag }} if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then docker buildx imagetools inspect ${{ steps.registries.outputs.docker_image }}:${{ steps.manifest.outputs.final_tag }} fi - name: Verify anonymous pulls on both architectures run: | set -euo pipefail registry_config=$(mktemp -d) trap 'rm -rf "$registry_config"' EXIT # Prevent Docker from discovering a system credential helper. printf '%s\n' '{"auths":{"ghcr.io":{},"https://index.docker.io/v1/":{}}}' > "$registry_config/config.json" images=("${{ steps.registries.outputs.ghcr_image }}") if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then images+=("${{ steps.registries.outputs.docker_image }}") fi for image in "${images[@]}"; do for platform in linux/amd64 linux/arm64; do docker --config "$registry_config" pull --quiet --platform "$platform" \ "$image:${{ steps.manifest.outputs.final_tag }}" done done - name: Redeploy Stack if: ${{ needs.mode.outputs.release == 'true' && env.DEPLOY == 'true' }} uses: appleboy/ssh-action@v1 with: key: ${{ secrets.SSH_KEY }} host: ${{ secrets.SSH_HOST }} username: ${{ secrets.SSH_USER }} script: | cd docker ./manage_stack.sh up reactive_resume - name: Purge Cloudflare cache if: ${{ needs.mode.outputs.release == 'true' && env.PURGE_CLOUDFLARE == 'true' }} env: CLOUDFLARE_ZONE_ID: ${{ secrets.CLOUDFLARE_ZONE_ID }} CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} run: | set -euo pipefail response=$(curl -fsS --max-time 10 --retry 3 --retry-delay 5 --retry-connrefused -X POST \ "https://api.cloudflare.com/client/v4/zones/${CLOUDFLARE_ZONE_ID}/purge_cache" \ -H "Authorization: Bearer ${CLOUDFLARE_API_TOKEN}" \ -H "Content-Type: application/json" \ --data '{"purge_everything":true}') if [ "$(jq -r '.success' <<< "$response")" != "true" ]; then echo "$response" | jq . exit 1 fi echo "Cloudflare cache purged successfully."