Skip to content

Build GHCR gcp-workertools image #18

Build GHCR gcp-workertools image

Build GHCR gcp-workertools image #18

name: Build GHCR gcp-workertools image
permissions:
packages: write
on:
push:
branches:
- main
paths:
- gcp/**
schedule:
- cron: '0 6 * * *'
workflow_dispatch:
env:
REGISTRY_IMAGE_BASE: ghcr.io/octopusdeploylabs/workertools
REGISTRY_IMAGE: ghcr.io/octopusdeploylabs/gcp-workertools
jobs:
get-version-number:
runs-on: windows-latest
outputs:
CONTINUE: ${{ steps.check-version.outputs.CONTINUE }}
VERSION: ${{ steps.check-version.outputs.VERSION }}
WIN2022_VERSION: ${{ steps.check-version.outputs.WIN2022_VERSION }}
steps:
- uses: actions/checkout@v4
- id: check-version
name: Compare latest version with container
run: |
Write-Output "Getting GCLOUD CLI version (needed for gke-auth-plugin)"
$googleCloudSdkInfo = Invoke-RestMethod "https://registry.hub.docker.com/v2/repositories/google/cloud-sdk/tags?page=1"
$otherImages = $googleCloudSdkInfo.results | Where-Object { $_.name -ine "latest" }
$latestTag = $googleCloudSdkInfo.results | Where-Object { $_.name -ieq "latest" }
if($null -eq $latestTag) {
throw "Couldnt find latest tag for Google Cloud SDK version from DockerHub"
}
$latestTagImage = $latestTag.images | Where-Object {$_.os -ieq "linux" -and $_.architecture -ieq "amd64" -and $_.status -ieq "active"} | Select-Object -First 1
if($null -eq $latestTagImage) {
throw "Couldnt find latest tag image for Google Cloud SDK version for linux/amd64"
}
$latestDigest = $latestTagImage.digest
Write-Output "Found latest digest: $latestDigest"
$versionToCompare = ""
foreach($result in $otherImages) {
$matchingImageDigest = $result.images | Where-Object {$_.os -ieq "linux" -and $_.architecture -ieq "amd64" -and $_.status -ieq "active" -and $_.digest -ieq $latestDigest } | Select-Object -First 1
if($null -eq $matchingImageDigest) {
continue;
}
else {
$version = $result.name
Write-Output "Found version '$version' that matches digest: $latestDigest"
$versionSplit = $version.Split(".")
$versionToCompare = "$($versionSplit[0]).$($versionSplit[1]).$($versionSplit[2])"
break;
}
}
if ([string]::IsNullOrWhiteSpace($versionToCompare)) {
throw "No version with digest $latestDigest found"
}
$token = [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes("${{ secrets.GITHUB_TOKEN }}"))
$workerToolsTags = Invoke-RestMethod -Uri "https://ghcr.io/v2/${{ env.REGISTRY_IMAGE }}/tags/list" -Headers @{Authorization="Bearer $token"} -SkipHttpErrorCheck
$matchingTag = $workerToolsTags.tags | Where-Object { $_ -eq $versionToCompare }
echo "VERSION=$versionToCompare" >> $env:GITHUB_OUTPUT
if ($null -ne $matchingTag -or ($null -ne $workerToolsTags.errors -and $workerToolsTags.errors[0].code -ne "NAME_UNKNOWN"))
{
Write-Host "Docker container already has latest version"
echo "CONTINUE=No" >> $env:GITHUB_OUTPUT
}
else
{
Write-Host "We need to upgrade the container to $versionToCompare"
Write-Host "Getting OS versions for windows 2022"
$win2022_manifest = (docker manifest inspect --verbose "mcr.microsoft.com/dotnet/framework/runtime:4.8.1-windowsservercore-ltsc2022" | ConvertFrom-Json)
$WIN2022_VERSION = $win2022_manifest.Descriptor.Platform.'os.version'
Write-Host "WIN2022_VERSION: $WIN2022_VERSION"
if([string]::IsNullOrWhiteSpace($WIN2022_VERSION)) {
throw "Could not establish OS versions for windows 2022 needed for docker manifest"
}
echo "WIN2022_VERSION=$WIN2022_VERSION" >> $env:GITHUB_OUTPUT
Write-Host "We have everything we need, continuing."
echo "CONTINUE=Yes" >> $env:GITHUB_OUTPUT
}
shell: pwsh
build-linux:
needs: [get-version-number]
if: ${{ needs.get-version-number.outputs.CONTINUE == 'Yes' }}
strategy:
matrix:
os:
- ubuntu-latest
platform:
- linux/amd64
- linux/arm64
runs-on: ${{ matrix.os }}
env:
VERSION_NUMBER: ${{ needs.get-version-number.outputs.VERSION }}-0
steps:
- name: Prepare
run: |
platform=${{ matrix.platform }}
echo "PLATFORM_PAIR=${platform//\//-}" >> $GITHUB_ENV
echo "PLATFORM_ARCH=${platform//[linux\/]/}" >> $GITHUB_ENV
- name: Checkout
uses: actions/checkout@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
with:
platforms: linux/amd64,linux/arm64
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GHCR
uses: docker/login-action@v3
with:
registry: https://ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push by digest
id: build
uses: docker/build-push-action@v5
with:
context: gcp/${{ env.PLATFORM_PAIR }}
platforms: ${{ matrix.platform }}
provenance: false
build-args: |
BASE_IMAGE=${{ env.REGISTRY_IMAGE_BASE }}
GCLOUD_CLI_VERSION=${{ env.VERSION_NUMBER }}
outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true
- name: Export digest
run: |
mkdir -p /tmp/digests
digest="${{ steps.build.outputs.digest }}"
touch "/tmp/digests/${digest#sha256:}"
- name: Upload digest
uses: actions/upload-artifact@v4
with:
name: digests-${{ env.PLATFORM_PAIR }}
path: /tmp/digests/*
if-no-files-found: error
retention-days: 1
build-win-2022:
needs: [get-version-number]
if: ${{ needs.get-version-number.outputs.CONTINUE == 'Yes' }}
runs-on: windows-2022
env:
VERSION_NUMBER: ${{ needs.get-version-number.outputs.VERSION }}
steps:
- uses: actions/checkout@v4
- name: Login to GHCR
uses: docker/login-action@v3
with:
registry: https://ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build the win2022 image
working-directory: ./gcp
run: docker build ./windows-2022 --build-arg BASE_IMAGE=${{ env.REGISTRY_IMAGE_BASE}} --build-arg GCLOUD_CLI_VERSION=${{ env.VERSION_NUMBER}} --tag ${{ env.REGISTRY_IMAGE }}:${{ env.VERSION_NUMBER }}-win.2022
- name: Push the win2022 version-specific image
run: docker push ${{ env.REGISTRY_IMAGE }}:${{ env.VERSION_NUMBER }}-win.2022
- name: Export windows digest
run: |
New-Item -Type Directory -Path "$($env:TEMP)/digests" -Force
$imageManifestOutput = $(docker manifest inspect --verbose ${{ env.REGISTRY_IMAGE }}:${{ env.VERSION_NUMBER }}-win.2022)
$fullDigest = ($imageManifestOutput | ConvertFrom-Json).Descriptor.digest
$digest = $fulldigest -Replace "sha256:", ""
$winDigestPath = "$($env:TEMP)/digests/$digest"
New-Item -Type File -Path $winDigestPath
echo "WIN_DIGEST_PATH=$($env:TEMP)/digests" >> $env:GITHUB_ENV
- name: Upload windows digest
uses: actions/upload-artifact@v4
with:
name: digests-windows-amd64
path: ${{ env.WIN_DIGEST_PATH }}/*
if-no-files-found: error
retention-days: 1
merge:
needs: [get-version-number, build-linux, build-win-2022]
if: ${{ needs.get-version-number.outputs.CONTINUE == 'Yes' }}
runs-on: ubuntu-latest
env:
VERSION_NUMBER: ${{ needs.get-version-number.outputs.VERSION }}
steps:
- name: Download digests
uses: actions/download-artifact@v4
with:
path: /tmp/digests
pattern: digests-*
merge-multiple: true
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Docker meta
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY_IMAGE }}
tags: |
${{ env.VERSION_NUMBER }}
latest
- name: Login to GHCR
uses: docker/login-action@v3
with:
registry: https://ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Create manifest list and push
working-directory: /tmp/digests
run: |
docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \
$(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *)
- name: Inspect image
run: |
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.meta.outputs.version }}