name: Build and Publish Container Image # Modelled on activity-core/.forgejo/workflows/image.yaml — the fleet's # canonical image-publish pattern. Images are built by CI from a tarball of # the pushed commit, never from a workstation working tree, so the artifact's # provenance is a forge revision. on: push: branches: - main paths: - ".forgejo/workflows/image.yaml" - "Containerfile" - "src/**" - "pyproject.toml" - "README.md" - "LICENSE" workflow_dispatch: env: REGISTRY: forgejo.coulomb.social IMAGE_NAME: coulomb/tenant-engine DOCKER_HOST: tcp://127.0.0.1:2375 jobs: build-and-push: runs-on: container-build steps: - name: Build and push image env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | set -eu REF="${GITHUB_SHA:-main}" SHORT="${REF:0:7}" mkdir -p buildctx "${HOME}/bin" wget -qO /tmp/repo.tar.gz \ "https://forgejo.coulomb.social/${GITHUB_REPOSITORY}/archive/${SHORT}.tar.gz" tar xzf /tmp/repo.tar.gz -C buildctx --strip-components=1 wget -qO- https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \ | tar xz --strip-components=1 -C "${HOME}/bin" docker/docker export PATH="${HOME}/bin:${PATH}" echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" -u "${REGISTRY_USER}" --password-stdin IMAGE="${REGISTRY}/${IMAGE_NAME}" docker build -f buildctx/Containerfile -t "${IMAGE}:latest" -t "${IMAGE}:main-${SHORT}" buildctx docker push "${IMAGE}:latest" docker push "${IMAGE}:main-${SHORT}" echo "pushed ${IMAGE}:latest and ${IMAGE}:main-${SHORT}" - name: Report immutable digest run: | set -eu export PATH="${HOME}/bin:${PATH}" IMAGE="${REGISTRY}/${IMAGE_NAME}" SHORT="${GITHUB_SHA:0:7}" # Deployments pin by digest, never by tag -- print it for the rollout step. docker inspect --format='{{index .RepoDigests 0}}' "${IMAGE}:main-${SHORT}"