From e0a0a1688d33b225b570cc821259452ce614872e Mon Sep 17 00:00:00 2001 From: Vignesh Date: Tue, 6 Oct 2026 21:51:17 +0200 Subject: [PATCH 1/4] ci: add baseline ROS 2 CI image Signed-off-by: Vignesh --- .github/workflows/ci-image.yml | 54 ++++++++++++++++++++++++++++++++++ containers/ci/Dockerfile | 46 +++++++++++++++++++++++++++++ 2 files changed, 100 insertions(+) create mode 100644 .github/workflows/ci-image.yml create mode 100644 containers/ci/Dockerfile diff --git a/.github/workflows/ci-image.yml b/.github/workflows/ci-image.yml new file mode 100644 index 0000000..50d19d1 --- /dev/null +++ b/.github/workflows/ci-image.yml @@ -0,0 +1,54 @@ +name: Build CI Image + +on: + push: + branches: + - main + paths: + - "containers/ci/**" + - ".github/workflows/ci-image.yml" + + workflow_dispatch: + +permissions: + contents: read + packages: write + +env: + REGISTRY: ghcr.io + IMAGE_NAME: openamrobot/ci-ros2-jazzy + +jobs: + build-and-push: + name: Build and publish CI image + runs-on: ubuntu-24.04 + + steps: + - name: Check out repository + uses: actions/checkout@v4 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log in to GHCR + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Build and push CI image + id: build + uses: docker/build-push-action@v6 + with: + context: . + file: containers/ci/Dockerfile + push: true + tags: | + ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest + ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} + + - name: Print image digest + run: | + echo "Image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}" + echo "Digest: ${{ steps.build.outputs.digest }}" \ No newline at end of file diff --git a/containers/ci/Dockerfile b/containers/ci/Dockerfile new file mode 100644 index 0000000..90d366b --- /dev/null +++ b/containers/ci/Dockerfile @@ -0,0 +1,46 @@ +FROM ros:jazzy-ros-base@sha256:066420e07f60aa18262f2479981def87ebcfcec42eefb0c0c57c4a46098348ca + +ARG DEBIAN_FRONTEND=noninteractive + +# Common CI and ROS workspace tooling +RUN apt-get update && apt-get install -y --no-install-recommends \ + python3-colcon-common-extensions \ + python3-rosdep \ + python3-vcstool \ + git \ + curl \ + \ + # Platform ROS dependencies \ + ros-jazzy-nav2-bringup \ + ros-jazzy-nav2-common \ + ros-jazzy-slam-toolbox \ + ros-jazzy-nav2-bt-navigator \ + ros-jazzy-nav2-behaviors \ + ros-jazzy-nav2-controller \ + ros-jazzy-nav2-lifecycle-manager \ + ros-jazzy-nav2-map-server \ + ros-jazzy-nav2-amcl \ + ros-jazzy-nav2-planner \ + ros-jazzy-nav2-smoother \ + ros-jazzy-nav2-waypoint-follower \ + ros-jazzy-nav2-velocity-smoother \ + ros-jazzy-nav2-collision-monitor \ + ros-jazzy-opennav-docking \ + ros-jazzy-laser-filters \ + ros-jazzy-rviz2 \ + ros-jazzy-camera-ros \ + ros-jazzy-joint-state-publisher \ + ros-jazzy-joint-state-publisher-gui \ + ros-jazzy-xacro \ + ros-jazzy-ros-gz-sim \ + ros-jazzy-ros-gz-bridge \ + ros-jazzy-rplidar-ros \ + ros-jazzy-apriltag-msgs \ + ros-jazzy-apriltag-ros \ + ros-jazzy-nav2-msgs \ + ros-jazzy-robot-localization \ + ros-jazzy-topic-tools \ + ros-jazzy-rmw-cyclonedds-cpp \ + && rm -rf /var/lib/apt/lists/* + +ENV RMW_IMPLEMENTATION=rmw_cyclonedds_cpp \ No newline at end of file From 31c2913c959b6ebe49fa77024be2cfcf94394f70 Mon Sep 17 00:00:00 2001 From: Vignesh Date: Tue, 6 Oct 2026 23:18:49 +0200 Subject: [PATCH 2/4] ci: pin external actions by commit sha Signed-off-by: Arumuga Vignesh S R <129583467+wikki26@users.noreply.github.com> --- .github/workflows/ci-image.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci-image.yml b/.github/workflows/ci-image.yml index 50d19d1..a94c2d0 100644 --- a/.github/workflows/ci-image.yml +++ b/.github/workflows/ci-image.yml @@ -25,13 +25,13 @@ jobs: steps: - name: Check out repository - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 - name: Log in to GHCR - uses: docker/login-action@v3 + uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} @@ -39,7 +39,7 @@ jobs: - name: Build and push CI image id: build - uses: docker/build-push-action@v6 + uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2 with: context: . file: containers/ci/Dockerfile From d9290432dea3848ee6be12a1ef6723d93f3535bb Mon Sep 17 00:00:00 2001 From: Arumuga Vignesh S R <129583467+wikki26@users.noreply.github.com> Date: Thu, 8 Oct 2026 19:48:44 +0200 Subject: [PATCH 3/4] ci: validate Docker image on pull requests Signed-off-by: Arumuga Vignesh S R <129583467+wikki26@users.noreply.github.com> --- .github/workflows/ci-image.yml | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci-image.yml b/.github/workflows/ci-image.yml index a94c2d0..50bf8e2 100644 --- a/.github/workflows/ci-image.yml +++ b/.github/workflows/ci-image.yml @@ -1,6 +1,12 @@ + name: Build CI Image on: + pull_request: + paths: + - "containers/ci/**" + - ".github/workflows/ci-image.yml" + push: branches: - main @@ -12,7 +18,6 @@ on: permissions: contents: read - packages: write env: REGISTRY: ghcr.io @@ -20,9 +25,13 @@ env: jobs: build-and-push: - name: Build and publish CI image + name: Build CI image runs-on: ubuntu-24.04 + permissions: + contents: read + packages: write + steps: - name: Check out repository uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 @@ -31,24 +40,26 @@ jobs: uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 - name: Log in to GHCR + if: github.event_name == 'push' && github.ref == 'refs/heads/main' uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Build and push CI image + - name: Build CI image and publish from main id: build uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2 with: context: . file: containers/ci/Dockerfile - push: true + push: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }} tags: | ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} - - name: Print image digest + - name: Print published image digest + if: github.event_name == 'push' && github.ref == 'refs/heads/main' run: | echo "Image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}" - echo "Digest: ${{ steps.build.outputs.digest }}" \ No newline at end of file + echo "Digest: ${{ steps.build.outputs.digest }}" From a95e751e1cfa62d635ed68d94303e5925c1515e9 Mon Sep 17 00:00:00 2001 From: Arumuga Vignesh S R <129583467+wikki26@users.noreply.github.com> Date: Thu, 8 Oct 2026 20:29:19 +0200 Subject: [PATCH 4/4] fix(ci): remove legacy RPLIDAR driver from baseline image Signed-off-by: Arumuga Vignesh S R <129583467+wikki26@users.noreply.github.com> --- containers/ci/Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/containers/ci/Dockerfile b/containers/ci/Dockerfile index 90d366b..3e3c540 100644 --- a/containers/ci/Dockerfile +++ b/containers/ci/Dockerfile @@ -34,7 +34,6 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ ros-jazzy-xacro \ ros-jazzy-ros-gz-sim \ ros-jazzy-ros-gz-bridge \ - ros-jazzy-rplidar-ros \ ros-jazzy-apriltag-msgs \ ros-jazzy-apriltag-ros \ ros-jazzy-nav2-msgs \