Files
FileShare/.gitea/workflows/release-image.yml
T
SKYMirror b5f06d09b3
Release 镜像 / 测试(推送前置门禁) (push) Failing after 13s
Release 镜像 / 多架构构建并推送 ACR (push) Skipped
CI:Gitea Actions 工作流(零第三方 action,国内网络自包含)
- push/PR 触发:后端 gofmt/vet/test/build + health 冒烟,
  前端 npm ci/类型检查/构建 + 站内文档嵌入校验
- main/tag v* 触发 Release:先跑测试门禁,
  再 buildx 多架构(amd64/arm64)构建推送阿里云 ACR(provenance/sbom 关闭,
  规避 ACR 不识别 OCI empty manifest 的问题)
- 检出用 GITHUB_TOKEN 自克隆,不依赖 github.com 的外部 action
2026-09-05 06:07:46 +08:00

103 lines
3.4 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: Release 镜像
on:
push:
branches: [main]
tags: ["v*"]
workflow_dispatch:
env:
REGISTRY: registry.cn-hangzhou.aliyuncs.com
IMAGE: registry.cn-hangzhou.aliyuncs.com/skymirror/fileshare
jobs:
test:
name: 测试(推送前置门禁)
runs-on: ubuntu-latest
container:
image: golang:1.27.1-alpine
timeout-minutes: 30
steps:
- name: 安装工具并检出
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
apk add --no-cache git curl bash >/dev/null
git clone --depth=1 --branch "$GITHUB_REF_NAME" \
"https://oauth2:${GITHUB_TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git" .
- name: go vet + go test
working-directory: server
env:
GOCACHE: /tmp/.gocache
GOMODCACHE: /tmp/.gomodcache
CGO_ENABLED: "0"
run: |
go vet ./...
go test ./... -count=1
build-push:
name: 多架构构建并推送 ACR
needs: test
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- name: 安装工具并检出
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories
apk add --no-cache git curl bash >/dev/null
git clone --depth=1 --branch "$GITHUB_REF_NAME" \
"https://oauth2:${GITHUB_TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git" .
# 嵌入产物同步(保证二进制内前端与仓库一致)
if [ -f web-embed/index.html ]; then :; fi
- name: 安装 Docker CLI(挂宿主 daemon
run: apk add --no-cache docker-cli buildx >/dev/null
- name: 计算 tag 与平台
id: meta
env:
REF: ${{ gitea.ref }}
run: |
case "$REF" in
refs/tags/v*)
VER="${REF#refs/tags/v}"
echo "tags=${IMAGE}:${VER} ${IMAGE}:latest" >> "$GITHUB_OUTPUT"
echo "发布 tag: ${VER} + latest" ;;
*)
echo "tags=${IMAGE}:latest" >> "$GITHUB_OUTPUT"
echo "main 构建: latest" ;;
esac
- name: 登录阿里云 ACR
env:
ACR_USER: ${{ secrets.ACR_USERNAME }}
ACR_PASS: ${{ secrets.ACR_PASSWORD }}
run: |
PASS_LEN=${#ACR_PASS}
echo "ACR 用户: $ACR_USER (密码 ${PASS_LEN} 位)"
printf '%s' "$ACR_PASS" | docker login "$REGISTRY" -u "$ACR_USER" --password-stdin
- name: 多架构构建并推送
env:
TAGS: ${{ steps.meta.outputs.tags }}
# provenance/sbom 必须关:阿里云 ACR 不识别 OCI empty manifestattestation),
# 否则报 "denied: unknown manifest class for application/vnd.oci.empty.v1+json"
run: |
ARGS=""
for t in $TAGS; do ARGS="$ARGS -t $t"; done
docker buildx build \
--builder default \
--platform linux/amd64,linux/arm64 \
--provenance=false --sbom=false \
--push \
-f deploy/Dockerfile \
$ARGS \
.
- name: 校验远程 manifest(双架构)
run: docker buildx imagetools inspect "${IMAGE}:latest" | grep -E "linux/amd64|linux/arm64"