Skip to content

Publish Docker image #16

Publish Docker image

Publish Docker image #16

Workflow file for this run

name: Publish Docker image
permissions:
contents: read
on:
workflow_dispatch:
release:
types: [published]
jobs:
push_to_registry:
environment:
name: "docker-hub"
url: https://hub.docker.com/r/hickorydns/hickory-dns
name: Push Docker image to Docker hub
runs-on: ubuntu-latest
strategy:
fail-fast: false
max-parallel: 4
matrix:
include:
# All non supported by base image are commented
- { platform: "linux/arm64", platform-tag: "arm64" }
- { platform: "linux/amd64", platform-tag: "amd64" }
- { platform: "linux/arm/v7", platform-tag: "armv7" }
- { platform: "linux/arm/v6", platform-tag: "armv6" }
- { platform: "linux/ppc64le", platform-tag: "ppc64le" }
#- { platform: "linux/riscv64", platform-tag: "riscv64" }
- { platform: "linux/s390x", platform-tag: "s390x" }
- { platform: "linux/386", platform-tag: "386" }
#- { platform: "linux/mips64le", platform-tag: "mips64le" }
#- { platform: "linux/mips64", platform-tag: "mips64" }
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Login to DockerHub
uses: docker/login-action@v3
with:
registry: docker.io
username: ${{ secrets.DOCKER_HUB_USER }}
password: ${{ secrets.DOCKER_HUB_PASSWORD }}
# https://github.com/docker/setup-qemu-action
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
# https://github.com/docker/setup-buildx-action
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and push image
run: make build-alpine
env:
DOCKER_BUILDKIT: 1
ACTION: push
PLATFORM: "${{ matrix.platform }}"
IMAGE_TAG: "docker.io/hickorydns/hickory-dns:${{ matrix.platform-tag }}-latest"
# Disable provenance to remove the attestation from the pushed image
# See: https://github.com/docker/buildx/issues/1509
# It makes: docker.io/botsudo/docker-rustpython:<arch>-latest a manifest list
# And docker manifest create does not like that
EXTRA_ARGS: "--provenance=false"
- name: Test docker image
if: ${{ matrix.platform == 'linux/amd64' }}
run: make test-alpine
build-and-push-manifest:
name: Build and push the docker hub manifest
runs-on: ubuntu-latest
needs: push_to_registry
environment:
name: "docker-hub"
url: https://hub.docker.com/r/hickorydns/hickory-dns
steps:
- name: Login to DockerHub
uses: docker/login-action@v3
with:
registry: docker.io
username: ${{ secrets.DOCKER_HUB_USER }}
password: ${{ secrets.DOCKER_HUB_PASSWORD }}
- name: Create the manifest
env:
DOCKER_CLI_EXPERIMENTAL: enabled
run: |
docker manifest create docker.io/hickorydns/hickory-dns:latest \
docker.io/hickorydns/hickory-dns:arm64-latest \
docker.io/hickorydns/hickory-dns:amd64-latest \
docker.io/hickorydns/hickory-dns:armv7-latest \
docker.io/hickorydns/hickory-dns:armv6-latest \
docker.io/hickorydns/hickory-dns:ppc64le-latest \
docker.io/hickorydns/hickory-dns:s390x-latest \
docker.io/hickorydns/hickory-dns:386-latest
- name: Push the manifest
env:
DOCKER_CLI_EXPERIMENTAL: enabled
run: docker manifest push docker.io/hickorydns/hickory-dns:latest
- name: Inspect the manifest
run: docker manifest inspect docker.io/hickorydns/hickory-dns:latest
tags-cleanup:
runs-on: ubuntu-latest
needs: build-and-push-manifest
environment:
name: "docker-hub"
url: https://hub.docker.com/r/hickorydns/hickory-dns
name: Cleanup DockerHub build tags
steps:
- name: Install Docker hub-tool
run: |
curl -sL https://github.com/docker/hub-tool/releases/download/v0.4.5/hub-tool-linux-amd64.tar.gz -o hub-tool-linux.tar.gz
tar --strip-components=1 -xzf ./hub-tool-linux.tar.gz
./hub-tool --version
- name: Login to DockerHub using hub-tool
run: |
set -eu
# Fool the login command (https://github.com/docker/hub-tool/pull/198)
# ./hub-tool login
# Token commands thank to https://stackoverflow.com/a/59334315/5155484
HUB_TOKEN=$(curl -s -H "Content-Type: application/json" -X POST -d "{\"username\": \"$DOCKER_USERNAME\", \"password\": \"$DOCKER_PASSWORD\"}" https://hub.docker.com/v2/users/login/ | jq -r .token)
USERNAME="$(printf '%s:' "$DOCKER_USERNAME" | base64 -w0)"
USER_PASS="$(printf '%s:%s' "$DOCKER_USERNAME" "$DOCKER_PASSWORD" | base64 -w0)"
mkdir -p ~/.docker/
printf '{"auths": {"hub-tool": {"auth": "%s"}, "hub-tool-refresh-token": {"auth": "%s"}, "hub-tool-token": { "auth": "%s", "identitytoken": "%s"}}}' \
"$USER_PASS" "$USERNAME" \
"$USERNAME" "$HUB_TOKEN" \
> ~/.docker/config.json
env:
DOCKER_USERNAME: ${{ secrets.DOCKER_HUB_USER }}
DOCKER_PASSWORD: ${{ secrets.DOCKER_HUB_PASSWORD }}
- name: Remove DockerHub tags via hub-tool
run: |
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:arm64-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:amd64-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:armv7-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:armv6-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:ppc64le-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:s390x-latest || true
./hub-tool tag rm --verbose --force docker.io/hickorydns/hickory-dns:386-latest || true
./hub-tool tag ls --verbose docker.io/hickorydns/hickory-dns
- name: Logout hub-tool
if: always()
run: rm ~/.docker/config.json