From c677edba060b13081f1d8075b4c4762acc517f67 Mon Sep 17 00:00:00 2001 From: ryan Date: Mon, 1 Jun 2026 09:57:41 +0800 Subject: [PATCH] =?UTF-8?q?[=E6=96=B0=E5=A2=9E]=20action?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../{docker-image.yml => docker-agent.yml} | 177 +---------------- .github/workflows/docker-openflared.yml | 187 ++++++++++++++++++ .github/workflows/docker-relay.yml | 187 ++++++++++++++++++ .github/workflows/docker-server.yml | 187 ++++++++++++++++++ 4 files changed, 565 insertions(+), 173 deletions(-) rename .github/workflows/{docker-image.yml => docker-agent.yml} (51%) create mode 100644 .github/workflows/docker-openflared.yml create mode 100644 .github/workflows/docker-relay.yml create mode 100644 .github/workflows/docker-server.yml diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-agent.yml similarity index 51% rename from .github/workflows/docker-image.yml rename to .github/workflows/docker-agent.yml index 9e36ac5d..dce96ca5 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-agent.yml @@ -1,4 +1,4 @@ -name: Docker image builds +name: Docker image build (Agent) on: workflow_dispatch: @@ -46,175 +46,6 @@ jobs: POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" - echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV" - if [[ "${GITHUB_REF}" == refs/tags/* ]]; then - VERSION="${GITHUB_REF_NAME}" - elif [[ -n "$INPUT_VERSION" ]]; then - VERSION="$INPUT_VERSION" - elif [[ -n "$POINTED_TAG" ]]; then - VERSION="$POINTED_TAG" - else - echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 - exit 1 - fi - - echo "VERSION=$VERSION" >> "$GITHUB_ENV" - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Log into registry - uses: docker/login-action@v3 - with: - registry: ghcr.io - username: ${{ github.repository_owner }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Build and push - id: build - uses: docker/build-push-action@v6 - with: - context: ./openflare_server - file: ./openflare_server/Dockerfile - platforms: ${{ matrix.platform }} - outputs: type=image,name=${{ env.IMAGE }},push-by-digest=true,name-canonical=true,push=true - build-args: | - VERSION=${{ env.VERSION }} - cache-from: type=gha,scope=docker-${{ matrix.arch }} - cache-to: type=gha,mode=max,scope=docker-${{ matrix.arch }} - - - name: Export digest - shell: bash - run: | - mkdir -p /tmp/digests - touch "/tmp/digests/${DIGEST#sha256:}" - env: - DIGEST: ${{ steps.build.outputs.digest }} - - - name: Upload digest - uses: actions/upload-artifact@v4 - with: - name: digests-${{ matrix.arch }} - path: /tmp/digests/* - if-no-files-found: error - retention-days: 1 - - - name: Generate artifact attestation - uses: actions/attest-build-provenance@v3 - with: - subject-name: ${{ env.IMAGE }} - subject-digest: ${{ steps.build.outputs.digest }} - push-to-registry: true - - merge: - name: Merge multi-arch manifest - runs-on: ubuntu-24.04 - needs: build - steps: - - name: Checkout code - uses: actions/checkout@v4 - with: - fetch-tags: true - fetch-depth: 0 - persist-credentials: false - - - name: Set image metadata - shell: bash - env: - INPUT_VERSION: ${{ github.event.inputs.version }} - run: | - POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" - INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" - - echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV" - if [[ "${GITHUB_REF}" == refs/tags/* ]]; then - VERSION="${GITHUB_REF_NAME}" - elif [[ -n "$INPUT_VERSION" ]]; then - VERSION="$INPUT_VERSION" - elif [[ -n "$POINTED_TAG" ]]; then - VERSION="$POINTED_TAG" - else - echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 - exit 1 - fi - - echo "VERSION=$VERSION" >> "$GITHUB_ENV" - - - name: Download digests - uses: actions/download-artifact@v4 - with: - path: /tmp/digests - pattern: digests-* - merge-multiple: true - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Log into registry - uses: docker/login-action@v3 - with: - registry: ghcr.io - username: ${{ github.repository_owner }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Create and push manifest list - working-directory: /tmp/digests - shell: bash - run: | - shopt -s nullglob - references=() - for digest in *; do - references+=("${IMAGE}@sha256:${digest}") - done - - if [ ${#references[@]} -eq 0 ]; then - echo "No digests found in /tmp/digests" >&2 - exit 1 - fi - - if [[ "${VERSION}" =~ (alpha|beta|rc) ]]; then - FLOATING_TAG="beta" - else - FLOATING_TAG="latest" - fi - - docker buildx imagetools create \ - -t "${IMAGE}:${VERSION}" \ - -t "${IMAGE}:${FLOATING_TAG}" \ - "${references[@]}" - - - name: Inspect image - run: docker buildx imagetools inspect "${IMAGE}:${VERSION}" - - build-agent: - name: Build Agent (${{ matrix.arch }}) - strategy: - fail-fast: false - matrix: - include: - - arch: amd64 - platform: linux/amd64 - runner: ubuntu-24.04 - - arch: arm64 - platform: linux/arm64 - runner: ubuntu-24.04-arm - runs-on: ${{ matrix.runner }} - steps: - - name: Checkout code - uses: actions/checkout@v4 - with: - fetch-tags: true - fetch-depth: 0 - persist-credentials: false - - - name: Set image metadata - shell: bash - env: - INPUT_VERSION: ${{ github.event.inputs.version }} - run: | - POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" - INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" - echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}-agent" >> "$GITHUB_ENV" if [[ "${GITHUB_REF}" == refs/tags/* ]]; then VERSION="${GITHUB_REF_NAME}" @@ -275,10 +106,10 @@ jobs: subject-digest: ${{ steps.build.outputs.digest }} push-to-registry: true - merge-agent: - name: Merge Agent multi-arch manifest + merge: + name: Merge multi-arch manifest runs-on: ubuntu-24.04 - needs: build-agent + needs: build steps: - name: Checkout code uses: actions/checkout@v4 diff --git a/.github/workflows/docker-openflared.yml b/.github/workflows/docker-openflared.yml new file mode 100644 index 00000000..2e31fe3f --- /dev/null +++ b/.github/workflows/docker-openflared.yml @@ -0,0 +1,187 @@ +name: Docker image build (OpenFlared) + +on: + workflow_dispatch: + inputs: + version: + description: "Image version/tag to publish, for example v1.0.0-beta" + required: false + type: string + push: + tags: ["v*"] + +permissions: + contents: read + packages: write + attestations: write + id-token: write + +jobs: + build: + name: Build (${{ matrix.arch }}) + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + platform: linux/amd64 + runner: ubuntu-24.04 + - arch: arm64 + platform: linux/arm64 + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}-flared" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Build and push + id: build + uses: docker/build-push-action@v6 + with: + context: . + file: ./openflared/Dockerfile + platforms: ${{ matrix.platform }} + outputs: type=image,name=${{ env.IMAGE }},push-by-digest=true,name-canonical=true,push=true + build-args: | + VERSION=${{ env.VERSION }} + cache-from: type=gha,scope=docker-flared-${{ matrix.arch }} + cache-to: type=gha,mode=max,scope=docker-flared-${{ matrix.arch }} + + - name: Export digest + shell: bash + run: | + mkdir -p /tmp/flared-digests + touch "/tmp/flared-digests/${DIGEST#sha256:}" + env: + DIGEST: ${{ steps.build.outputs.digest }} + + - name: Upload digest + uses: actions/upload-artifact@v4 + with: + name: flared-digests-${{ matrix.arch }} + path: /tmp/flared-digests/* + if-no-files-found: error + retention-days: 1 + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ${{ env.IMAGE }} + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + + merge: + name: Merge multi-arch manifest + runs-on: ubuntu-24.04 + needs: build + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}-flared" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Download digests + uses: actions/download-artifact@v4 + with: + path: /tmp/flared-digests + pattern: flared-digests-* + merge-multiple: true + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Create and push manifest list + working-directory: /tmp/flared-digests + shell: bash + run: | + shopt -s nullglob + references=() + for digest in *; do + references+=("${IMAGE}@sha256:${digest}") + done + + if [ ${#references[@]} -eq 0 ]; then + echo "No digests found in /tmp/flared-digests" >&2 + exit 1 + fi + + if [[ "${VERSION}" =~ (alpha|beta|rc) ]]; then + FLOATING_TAG="beta" + else + FLOATING_TAG="latest" + fi + + docker buildx imagetools create \ + -t "${IMAGE}:${VERSION}" \ + -t "${IMAGE}:${FLOATING_TAG}" \ + "${references[@]}" + + - name: Inspect image + run: docker buildx imagetools inspect "${IMAGE}:${VERSION}" diff --git a/.github/workflows/docker-relay.yml b/.github/workflows/docker-relay.yml new file mode 100644 index 00000000..d06384a4 --- /dev/null +++ b/.github/workflows/docker-relay.yml @@ -0,0 +1,187 @@ +name: Docker image build (Relay) + +on: + workflow_dispatch: + inputs: + version: + description: "Image version/tag to publish, for example v1.0.0-beta" + required: false + type: string + push: + tags: ["v*"] + +permissions: + contents: read + packages: write + attestations: write + id-token: write + +jobs: + build: + name: Build (${{ matrix.arch }}) + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + platform: linux/amd64 + runner: ubuntu-24.04 + - arch: arm64 + platform: linux/arm64 + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}-relay" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Build and push + id: build + uses: docker/build-push-action@v6 + with: + context: . + file: ./openflare_relay/Dockerfile + platforms: ${{ matrix.platform }} + outputs: type=image,name=${{ env.IMAGE }},push-by-digest=true,name-canonical=true,push=true + build-args: | + VERSION=${{ env.VERSION }} + cache-from: type=gha,scope=docker-relay-${{ matrix.arch }} + cache-to: type=gha,mode=max,scope=docker-relay-${{ matrix.arch }} + + - name: Export digest + shell: bash + run: | + mkdir -p /tmp/relay-digests + touch "/tmp/relay-digests/${DIGEST#sha256:}" + env: + DIGEST: ${{ steps.build.outputs.digest }} + + - name: Upload digest + uses: actions/upload-artifact@v4 + with: + name: relay-digests-${{ matrix.arch }} + path: /tmp/relay-digests/* + if-no-files-found: error + retention-days: 1 + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ${{ env.IMAGE }} + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + + merge: + name: Merge multi-arch manifest + runs-on: ubuntu-24.04 + needs: build + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}-relay" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Download digests + uses: actions/download-artifact@v4 + with: + path: /tmp/relay-digests + pattern: relay-digests-* + merge-multiple: true + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Create and push manifest list + working-directory: /tmp/relay-digests + shell: bash + run: | + shopt -s nullglob + references=() + for digest in *; do + references+=("${IMAGE}@sha256:${digest}") + done + + if [ ${#references[@]} -eq 0 ]; then + echo "No digests found in /tmp/relay-digests" >&2 + exit 1 + fi + + if [[ "${VERSION}" =~ (alpha|beta|rc) ]]; then + FLOATING_TAG="beta" + else + FLOATING_TAG="latest" + fi + + docker buildx imagetools create \ + -t "${IMAGE}:${VERSION}" \ + -t "${IMAGE}:${FLOATING_TAG}" \ + "${references[@]}" + + - name: Inspect image + run: docker buildx imagetools inspect "${IMAGE}:${VERSION}" diff --git a/.github/workflows/docker-server.yml b/.github/workflows/docker-server.yml new file mode 100644 index 00000000..b69223f0 --- /dev/null +++ b/.github/workflows/docker-server.yml @@ -0,0 +1,187 @@ +name: Docker image build (Server) + +on: + workflow_dispatch: + inputs: + version: + description: "Image version/tag to publish, for example v1.0.0-beta" + required: false + type: string + push: + tags: ["v*"] + +permissions: + contents: read + packages: write + attestations: write + id-token: write + +jobs: + build: + name: Build (${{ matrix.arch }}) + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + platform: linux/amd64 + runner: ubuntu-24.04 + - arch: arm64 + platform: linux/arm64 + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Build and push + id: build + uses: docker/build-push-action@v6 + with: + context: ./openflare_server + file: ./openflare_server/Dockerfile + platforms: ${{ matrix.platform }} + outputs: type=image,name=${{ env.IMAGE }},push-by-digest=true,name-canonical=true,push=true + build-args: | + VERSION=${{ env.VERSION }} + cache-from: type=gha,scope=docker-server-${{ matrix.arch }} + cache-to: type=gha,mode=max,scope=docker-server-${{ matrix.arch }} + + - name: Export digest + shell: bash + run: | + mkdir -p /tmp/server-digests + touch "/tmp/server-digests/${DIGEST#sha256:}" + env: + DIGEST: ${{ steps.build.outputs.digest }} + + - name: Upload digest + uses: actions/upload-artifact@v4 + with: + name: server-digests-${{ matrix.arch }} + path: /tmp/server-digests/* + if-no-files-found: error + retention-days: 1 + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ${{ env.IMAGE }} + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true + + merge: + name: Merge multi-arch manifest + runs-on: ubuntu-24.04 + needs: build + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-tags: true + fetch-depth: 0 + persist-credentials: false + + - name: Set image metadata + shell: bash + env: + INPUT_VERSION: ${{ github.event.inputs.version }} + run: | + POINTED_TAG="$(git tag --points-at HEAD --list 'v*' | sort -V | tail -n1)" + INPUT_VERSION="${INPUT_VERSION//[[:space:]]/}" + + echo "IMAGE=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV" + if [[ "${GITHUB_REF}" == refs/tags/* ]]; then + VERSION="${GITHUB_REF_NAME}" + elif [[ -n "$INPUT_VERSION" ]]; then + VERSION="$INPUT_VERSION" + elif [[ -n "$POINTED_TAG" ]]; then + VERSION="$POINTED_TAG" + else + echo "workflow_dispatch requires an explicit version input when HEAD is not tagged" >&2 + exit 1 + fi + + echo "VERSION=$VERSION" >> "$GITHUB_ENV" + + - name: Download digests + uses: actions/download-artifact@v4 + with: + path: /tmp/server-digests + pattern: server-digests-* + merge-multiple: true + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log into registry + uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.repository_owner }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Create and push manifest list + working-directory: /tmp/server-digests + shell: bash + run: | + shopt -s nullglob + references=() + for digest in *; do + references+=("${IMAGE}@sha256:${digest}") + done + + if [ ${#references[@]} -eq 0 ]; then + echo "No digests found in /tmp/server-digests" >&2 + exit 1 + fi + + if [[ "${VERSION}" =~ (alpha|beta|rc) ]]; then + FLOATING_TAG="beta" + else + FLOATING_TAG="latest" + fi + + docker buildx imagetools create \ + -t "${IMAGE}:${VERSION}" \ + -t "${IMAGE}:${FLOATING_TAG}" \ + "${references[@]}" + + - name: Inspect image + run: docker buildx imagetools inspect "${IMAGE}:${VERSION}"