-
Notifications
You must be signed in to change notification settings - Fork 7
160 lines (142 loc) · 6.04 KB
/
Copy pathimage.yaml
File metadata and controls
160 lines (142 loc) · 6.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
name: Build and Publish Rocks
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
prepare:
runs-on: ubuntu-latest
outputs:
ghcr-upload: ${{ steps.read-ci-config.outputs.ghcr-upload }}
build-matrix: ${{ steps.read-ci-config.outputs.build-matrix }}
upload-matrix: ${{ steps.read-ci-config.outputs.upload-matrix }}
arch-map: ${{ steps.set-map.outputs.arch-map }}
steps:
- name: Checkout Repository
uses: actions/checkout@v5
- name: Read .github/ci.yaml
id: read-ci-config
uses: canonical/rocks-template-actions/actions/read-ci-config@v1
- name: Set Architecture Map
id: set-map
run: |
if [[ "${{ github.repository_owner }}" != "canonical" ]]; then
echo 'arch-map={"amd64":["ubuntu-24.04"],"arm64":["ubuntu-24.04-arm"]}' >> $GITHUB_OUTPUT
fi
# TODO: remove once the pro-feature is stable in rockcraft
# Warn the user if using tests in a pro enabled build
- name: Check Pro and Test Incompatibility
run: |
build_matrix='${{ steps.read-ci-config.outputs.build-matrix }}'
# Use jq to iterate over the 'include' array
echo "$build_matrix" | jq -c '.include[]' | while read -r row; do
directory=$(echo "$row" | jq -r '.["directory"] // "unknown"')
pro_services=$(echo "$row" | jq -r '.["pro-services"] // ""')
run_tests=$(echo "$row" | jq -r '.["run-tests"] // "false"')
if [[ -n "$pro_services" && "$run_tests" == "true" ]]; then
echo "::warning::Tests for Pro Services are currently not supported. Rockcraft tests will be skipped for ${directory}."
fi
done
build:
needs: [prepare]
strategy:
matrix: ${{ fromJSON(needs.prepare.outputs.build-matrix) }}
uses: canonical/oci-factory/.github/workflows/Build-Rock.yaml@main
with:
rock-repo: ${{ github.event.pull_request.head.repo.full_name || github.repository }}
rock-repo-commit: ${{ github.head_ref || github.ref_name }}
rockfile-directory: ${{ matrix.directory }}
oci-archive-name: ${{ matrix.artifact-name }}
arch-map: ${{ needs.prepare.outputs.arch-map }}
rockcraft-test: ${{ matrix.run-tests }}
pro-services: ${{ matrix.pro-services }}
secrets:
source-github-token: ${{ secrets.REPO_CLONER_TOKEN }}
pro-token: ${{ secrets[matrix.pro-token] }}
pro-artifact-passphrase: ${{ secrets[matrix.pro-artifact-passphrase] }}
test:
needs: [prepare, build]
strategy:
fail-fast: false
matrix: ${{ fromJSON(needs.prepare.outputs.build-matrix) }}
uses: canonical/oci-factory/.github/workflows/Test-Rock.yaml@main
with:
oci-archive-name: ${{ matrix.artifact-name }}
secrets:
pro-artifact-passphrase: ${{ secrets[matrix.pro-artifact-passphrase] }}
upload-ghcr:
needs: [prepare, test]
runs-on: ubuntu-latest
if: |
needs.prepare.outputs.ghcr-upload == 'true' &&
github.event_name != 'pull_request' &&
github.ref == 'refs/heads/main'
strategy:
matrix: ${{ fromJSON(needs.prepare.outputs.build-matrix) }}
fail-fast: false
permissions:
packages: write
steps:
- name: Pre-Check Pro Enabled Rocks
if: ${{ github.event.repository.visibility == 'public' && matrix.pro-services != '' }}
run: |
echo "::warning::Uploading Pro enabled rocks to GHCR is not allowed for public repositories."
- name: Upload Rock to GHCR
if: ${{ github.event.repository.visibility != 'public' || matrix.pro-services == '' }}
uses: canonical/oci-factory/.github/actions/upload-rock@main
with:
artifact_name: ${{ matrix.artifact-name }}
tags: ${{ matrix.tag }}
name: ${{ matrix.name }}
registry: ghcr.io/${{ github.repository }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
decrypt-passphrase: ${{ secrets[matrix.pro-artifact-passphrase] }}
upload-registries:
needs: [prepare, test]
runs-on: ubuntu-latest
if: |
needs.prepare.outputs.upload-matrix != '{"include": []}' &&
github.event_name != 'pull_request' &&
github.ref == 'refs/heads/main'
strategy:
matrix: ${{ fromJSON(needs.prepare.outputs.upload-matrix) }}
fail-fast: false
steps:
- name: Prepare ECR Session Token
if: ${{ contains(matrix.registry-auth-method, 'ecr') }}
id: get-ecr-token
env:
AWS_ACCESS_KEY_ID: ${{ secrets[matrix.registry-auth-username] }}
AWS_SECRET_ACCESS_KEY: ${{ secrets[matrix.registry-auth-password] }}
run: |
session_token=$(aws ${{ matrix.registry-auth-method }} \
get-login-password \
--region ${{ matrix.registry-auth-region }} \
)
echo "::add-mask::$session_token"
echo "aws-session-token=$session_token" >> $GITHUB_OUTPUT
- name: Upload Rock to ECR
uses: canonical/oci-factory/.github/actions/upload-rock@main
if: ${{ contains(matrix.registry-auth-method, 'ecr') }}
with:
artifact_name: ${{ matrix.artifact-name }}
tags: ${{ matrix.tag }}
name: ${{ matrix.name }}
registry: ${{ matrix.registry-uri }}
username: AWS
password: ${{ steps.get-ecr-token.outputs.aws-session-token }}
decrypt-passphrase: ${{ secrets[matrix.pro-artifact-passphrase] }}
- name: Upload Rock to Registry
uses: canonical/oci-factory/.github/actions/upload-rock@main
if: matrix.registry-auth-method == 'basic'
with:
artifact_name: ${{ matrix.artifact-name }}
tags: ${{ matrix.tag }}
name: ${{ matrix.name }}
registry: ${{ matrix.registry-uri }}
username: ${{ secrets[matrix.registry-auth-username] }}
password: ${{ secrets[matrix.registry-auth-password] }}
decrypt-passphrase: ${{ secrets[matrix.pro-artifact-passphrase] }}