Skip to content

ci: publish website Docker image to GHCR; standalone compose #4

ci: publish website Docker image to GHCR; standalone compose

ci: publish website Docker image to GHCR; standalone compose #4

Workflow file for this run

name: Docker image
on:
push:
branches: [main]
tags: ['v*']
pull_request:
branches: [main]
workflow_dispatch:
env:
REGISTRY: ghcr.io
# github.repository_owner preserves the owner's display case (e.g.
# `IamCoder18`). GHCR resolves package lookups case-insensitively at the
# storage layer, so `ghcr.io/IamCoder18/synapse-website` and
# `ghcr.io/iamcoder18/synapse-website` point at the same package — we use
# the lowercase spelling in the docker-compose files purely for
# readability.
IMAGE_NAME: ${{ github.repository_owner }}/synapse-website
jobs:
build:
name: Build & push image
runs-on: ubuntu-latest
# Publish only on direct pushes to main or on v* tags. PRs run the
# build-pr job (push: false, no cache-to) below.
if: github.event_name != 'pull_request'
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=sha,format=short
type=raw,value=latest,enable={{is_default_branch}}
- name: Build and push
uses: docker/bake-action@v5
with:
# `files` paths are resolved relative to the action's working
# directory (the repo root after checkout). The bake target's
# own `context` controls where the Dockerfile and source files
# are read from.
files: |
website/docker-bake.hcl
targets: synapse-website
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-pr:
name: Build (PR only)
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build
uses: docker/bake-action@v5
with:
files: |
website/docker-bake.hcl
# Use the dedicated PR target, which omits `cache-to` because
# fork PRs lack permission to write to the GHA cache.
targets: synapse-website-pr
push: false