name: Publish Docker image on: workflow_dispatch: inputs: version: description: 'Image tag to publish, for example MeBox-v0.0.32' required: true type: string ref: description: 'Git ref to build from' required: false default: main type: string permissions: contents: read packages: write jobs: docker: runs-on: ubuntu-latest env: RELEASE_VERSION: ${{ github.event_name == 'workflow_dispatch' && inputs.version || github.ref_name }} steps: - uses: actions/checkout@v4 with: ref: ${{ github.event_name == 'workflow_dispatch' && inputs.ref || github.ref }} - uses: docker/setup-qemu-action@v3 - uses: docker/setup-buildx-action@v3 - name: Log in to GHCR uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract image metadata id: meta uses: docker/metadata-action@v5 with: # 自动使用当前仓库所有者 images: ghcr.io/${{ github.repository_owner }}/mebox tags: | type=raw,value=latest type=raw,value=${{ env.RELEASE_VERSION }} - name: Build & push uses: docker/build-push-action@v6 with: context: . platforms: linux/amd64,linux/arm64 push: true provenance: false sbom: false tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} build-args: | VERSION=${{ env.RELEASE_VERSION }} cache-from: type=gha cache-to: type=gha,mode=max deploy: name: Deploy to Server needs: [docker] runs-on: ubuntu-latest steps: - name: Deploy via SSH uses: appleboy/ssh-action@v1.0.3 with: host: ${{ secrets.SERVER_HOST }} username: ${{ secrets.SERVER_USER }} password: ${{ secrets.SERVER_PASSWORD }} port: ${{ secrets.SERVER_PORT }} script: | set -e echo "==== 开始部署 MeBox ====" cd /root/dockerData/mebox if docker compose version >/dev/null 2>&1; then COMPOSE_CMD="docker compose" elif command -v docker-compose >/dev/null 2>&1; then COMPOSE_CMD="docker-compose" else echo "错误: 未找到 docker compose 或 docker-compose" exit 1 fi echo "正在拉取最新镜像..." $COMPOSE_CMD pull echo "正在重启服务..." $COMPOSE_CMD up -d echo "清理旧的无用镜像..." docker image prune -f echo "==== 部署完成并已启动 ===="