ci: add dispatch-only kaniko-act build, targeting the org registry
Bootstrap step for moving container images off the personal namespace. Builds using the existing mikkeli/kaniko-act; the org copy is what this run produces.
This commit is contained in:
@@ -0,0 +1,60 @@
|
|||||||
|
# Rebuilds the kaniko-act builder image.
|
||||||
|
#
|
||||||
|
# Dispatch-only on purpose. This is the image build-image.yml runs inside, so
|
||||||
|
# an automatic trigger could push a broken builder and take the whole build
|
||||||
|
# path down with it. Bump deliberately, verify, then repoint build-image.yml.
|
||||||
|
#
|
||||||
|
# Self-hosting: builds the new kaniko-act using the *previous* kaniko-act, per
|
||||||
|
# the bootstrap note in ci/Dockerfile.kaniko-act.
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
VERSION:
|
||||||
|
description: "Tag to publish, e.g. v1.23.2-r2"
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
default: v1.23.2-r2
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
container:
|
||||||
|
# BOOTSTRAP: still the pre-migration image under `mikkeli`, because the
|
||||||
|
# org copy is what this run creates. Flip to the org path once it exists.
|
||||||
|
image: pi5-16.local:3005/mikkeli/kaniko-act:v1.23.2-r2
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Fetch source, build, push
|
||||||
|
# kaniko image has no bash — busybox sh only
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
# package r/w PAT (org-level secret) — registry push only
|
||||||
|
PKG_TOKEN: ${{ secrets.PKGRW_PAT }}
|
||||||
|
# per-run auto-token, read access to this repo only — source fetch
|
||||||
|
JOB_TOKEN: ${{ github.token }}
|
||||||
|
URL_TO_GITEA: ${{ vars.URL_TO_GITEA }}
|
||||||
|
VERSION: ${{ inputs.VERSION }}
|
||||||
|
run: |
|
||||||
|
set -eu
|
||||||
|
HOST="${URL_TO_GITEA#http://}"
|
||||||
|
IMAGE="${HOST}/novoyuuparosk-wiki/kaniko-act"
|
||||||
|
|
||||||
|
wget -qO /tmp/src.tar.gz \
|
||||||
|
"http://mikkeli:${JOB_TOKEN}@${HOST}/api/v1/repos/novoyuuparosk-wiki/novoyuuparosk-auto-wiki/archive/${GITHUB_SHA}.tar.gz"
|
||||||
|
mkdir -p /tmp/src
|
||||||
|
tar -xzf /tmp/src.tar.gz -C /tmp/src --strip-components=1
|
||||||
|
|
||||||
|
# Registry auth for the push
|
||||||
|
AUTH=$(printf '%s' "mikkeli:${PKG_TOKEN}" | base64 | tr -d '\n')
|
||||||
|
printf '{"auths":{"%s":{"auth":"%s"}}}' "${HOST}" "${AUTH}" \
|
||||||
|
> /kaniko/.docker/config.json
|
||||||
|
|
||||||
|
# --insecure: push target is the plain-HTTP Gitea registry.
|
||||||
|
# Base image pull (gcr.io) stays HTTPS — no --insecure-pull.
|
||||||
|
/kaniko/executor \
|
||||||
|
--context dir:///tmp/src \
|
||||||
|
--dockerfile /tmp/src/ci/Dockerfile.kaniko-act \
|
||||||
|
--destination "${IMAGE}:${VERSION}" \
|
||||||
|
--insecure
|
||||||
|
|
||||||
|
echo "Pushed ${IMAGE}:${VERSION}"
|
||||||
Reference in New Issue
Block a user