Files
FileShare/.gitea/workflows/release-image.yml
T
SKYMirror 27b8b75136
Release 镜像 / 测试(推送前置门禁) (push) Successful in 47s
Release 镜像 / 多架构构建并推送 ACR (push) Failing after 1s
CI 修复:clone URL 自适应 http/https(GITHUB_SERVER_URL 为内网地址时的 scheme 处理)
2026-09-05 06:36:17 +08:00

114 lines
4.0 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: Release 镜像
on:
push:
branches: [main]
tags: ["v*", "26.*", "27.*"]
workflow_dispatch:
env:
REGISTRY: registry.cn-hangzhou.aliyuncs.com
IMAGE: registry.cn-hangzhou.aliyuncs.com/skymirror/fileshare
jobs:
test:
name: 测试(推送前置门禁)
runs-on: ubuntu-latest
container:
image: golang:1.27.1-alpine
timeout-minutes: 30
steps:
- name: 安装工具并检出
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
apk add --no-cache git curl bash >/dev/null
SCHEME="${GITHUB_SERVER_URL%%://*}"
SRV="${GITHUB_SERVER_URL#*://}"
echo "clone from ${SCHEME}://${SRV}"
git clone --depth=1 --branch "$GITHUB_REF_NAME" \
"${SCHEME}://oauth2:${GITHUB_TOKEN}@${SRV}/${GITHUB_REPOSITORY}.git" .
- name: go vet + go test
working-directory: server
env:
GOCACHE: /tmp/.gocache
GOMODCACHE: /tmp/.gomodcache
CGO_ENABLED: "0"
run: |
go vet ./...
go test ./... -count=1
build-push:
name: 多架构构建并推送 ACR
needs: test
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- name: 安装工具并检出
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
apk add --no-cache git curl bash >/dev/null
SCHEME="${GITHUB_SERVER_URL%%://*}"
SRV="${GITHUB_SERVER_URL#*://}"
echo "clone from ${SCHEME}://${SRV}"
git clone --depth=1 --branch "$GITHUB_REF_NAME" \
"${SCHEME}://oauth2:${GITHUB_TOKEN}@${SRV}/${GITHUB_REPOSITORY}.git" .
# 嵌入产物同步(保证二进制内前端与仓库一致)
if [ -f web-embed/index.html ]; then :; fi
- name: 安装 Docker CLI(挂宿主 daemon
run: apk add --no-cache docker-cli buildx >/dev/null
- name: 计算 tag(以 APP_VERSION 为唯一版本源)
id: meta
env:
REF: ${{ gitea.ref }}
run: |
VER=$(sed -n 's/.*APP_VERSION = "\(.*\)".*/\1/p' server/cmd/server/main.go | head -1)
[ -n "$VER" ] || { echo "无法从 main.go 解析 APP_VERSION" >&2; exit 1; }
echo "APP_VERSION=$VER"
if [[ "$REF" == refs/tags/* ]]; then
# tag 触发:要求 tag 名与 APP_VERSION 一致,防错版发布
TAG_VER="${REF#refs/tags/}"
TAG_VER="${TAG_VER#v}"
[ "$TAG_VER" = "$VER" ] || { echo "tag($TAG_VER) != APP_VERSION($VER),拒绝发布" >&2; exit 1; }
fi
echo "tags=${IMAGE}:${VER} ${IMAGE}:latest" >> "$GITHUB_OUTPUT"
- name: 登录阿里云 ACR
env:
ACR_USER: ${{ secrets.ACR_USERNAME }}
ACR_PASS: ${{ secrets.ACR_PASSWORD }}
run: |
PASS_LEN=${#ACR_PASS}
echo "ACR 用户: $ACR_USER (密码 ${PASS_LEN} 位)"
printf '%s' "$ACR_PASS" | docker login "$REGISTRY" -u "$ACR_USER" --password-stdin
- name: 多架构构建并推送
env:
TAGS: ${{ steps.meta.outputs.tags }}
# provenance/sbom 必须关:阿里云 ACR 不识别 OCI empty manifestattestation),
# 否则报 "denied: unknown manifest class for application/vnd.oci.empty.v1+json"
run: |
ARGS=""
for t in $TAGS; do ARGS="$ARGS -t $t"; done
docker buildx build \
--builder default \
--platform linux/amd64,linux/arm64 \
--provenance=false --sbom=false \
--push \
-f deploy/Dockerfile \
$ARGS \
.
- name: 校验远程 manifest(双架构)
env:
VERSION: ${{ steps.meta.outputs.version }}
run: |
docker buildx imagetools inspect "${IMAGE}:${VERSION}" | grep -E "linux/amd64|linux/arm64"
echo "推送完成: ${IMAGE}:${VERSION} + ${IMAGE}:latest"