name: Docker image builds on: workflow_dispatch: push: tags: ["v*"] permissions: contents: read packages: write attestations: write id-token: write jobs: build: runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 with: fetch-tags: true fetch-depth: 0 persist-credentials: false - name: Set lowercase image name id: meta shell: bash run: | echo "image=ghcr.io/${GITHUB_REPOSITORY,,}" >> "$GITHUB_OUTPUT" echo "version=$(git describe --tags)" >> "$GITHUB_OUTPUT" - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log into registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.repository_owner }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and push id: build uses: docker/build-push-action@v6 with: context: ./atsf_server file: ./atsf_server/Dockerfile push: true tags: | ${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }} ${{ steps.meta.outputs.image }}:latest build-args: | VERSION=${{ steps.meta.outputs.version }} cache-from: type=gha cache-to: type=gha,mode=max platforms: linux/amd64,linux/arm64 - name: Generate artifact attestation uses: actions/attest-build-provenance@v3 with: subject-name: ${{ steps.meta.outputs.image }} subject-digest: ${{ steps.build.outputs.digest }} push-to-registry: true