name: Release on: workflow_dispatch: permissions: contents: write issues: write pull-requests: write packages: write jobs: release: name: Semantic Release runs-on: ubuntu-latest outputs: new_version: ${{ steps.check.outputs.version }} steps: - name: Checkout uses: actions/checkout@v4 with: fetch-depth: 0 persist-credentials: false - name: Setup pnpm uses: pnpm/action-setup@v4 - name: Setup Node.js uses: actions/setup-node@v4 with: node-version: 22 cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Run semantic-release env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: npx semantic-release - name: Check for new release id: check run: | if [ -f .release-version ]; then echo "version=$(cat .release-version)" >> "$GITHUB_OUTPUT" else echo "::error::semantic-release did not produce a new version. No releasable commits found." exit 1 fi docker: name: Build (${{ matrix.platform }}) needs: release strategy: fail-fast: false matrix: include: - platform: linux/amd64 runner: ubuntu-latest - platform: linux/arm64 runner: ubuntu-24.04-arm runs-on: ${{ matrix.runner }} steps: - name: Free disk space run: | sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc \ /usr/local/share/boost /opt/hostedtoolcache/CodeQL sudo docker system prune -af df -h / - name: Prepare run: | platform=${{ matrix.platform }} echo "PLATFORM_PAIR=${platform//\//-}" >> $GITHUB_ENV - name: Checkout release tag uses: actions/checkout@v4 with: ref: v${{ needs.release.outputs.new_version }} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to Docker Hub uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Log in to GitHub Container Registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta uses: docker/metadata-action@v5 with: images: | stirlingimage/stirling-image ghcr.io/${{ github.repository }} - name: Build and push by digest id: build uses: docker/build-push-action@v6 with: context: . file: docker/Dockerfile platforms: ${{ matrix.platform }} labels: ${{ steps.meta.outputs.labels }} outputs: type=image,"name=stirlingimage/stirling-image,ghcr.io/${{ github.repository }}",push-by-digest=true,name-canonical=true,push=true cache-from: type=gha,scope=${{ env.PLATFORM_PAIR }} cache-to: type=gha,mode=max,scope=${{ env.PLATFORM_PAIR }} - name: Export digest run: | mkdir -p /tmp/digests digest="${{ steps.build.outputs.digest }}" touch "/tmp/digests/${digest#sha256:}" - name: Upload digest uses: actions/upload-artifact@v4 with: name: digests-${{ env.PLATFORM_PAIR }} path: /tmp/digests/* if-no-files-found: error retention-days: 1 manifest: name: Create Multi-Arch Manifests needs: [release, docker] runs-on: ubuntu-latest steps: - name: Download digests uses: actions/download-artifact@v4 with: path: /tmp/digests pattern: digests-* merge-multiple: true - name: Log in to Docker Hub uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Log in to GitHub Container Registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta uses: docker/metadata-action@v5 with: images: | stirlingimage/stirling-image ghcr.io/${{ github.repository }} tags: | type=semver,pattern={{version}},value=v${{ needs.release.outputs.new_version }} type=semver,pattern={{major}}.{{minor}},value=v${{ needs.release.outputs.new_version }} type=semver,pattern={{major}},value=v${{ needs.release.outputs.new_version }} type=raw,value=latest - name: Create Docker Hub manifest working-directory: /tmp/digests run: | docker buildx imagetools create \ $(jq -cr '.tags | map(select(startswith("stirlingimage/")) | "-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ $(printf 'stirlingimage/stirling-image@sha256:%s ' *) - name: Create GHCR manifest working-directory: /tmp/digests run: | docker buildx imagetools create \ $(jq -cr '.tags | map(select(startswith("ghcr.io/")) | "-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ $(printf 'ghcr.io/${{ github.repository }}@sha256:%s ' *)