Repository navigation
ci: publish website Docker image to GHCR; standalone compose #4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Docker image | |
| on: | |
| push: | |
| branches: [main] | |
| tags: ['v*'] | |
| pull_request: | |
| branches: [main] | |
| workflow_dispatch: | |
| env: | |
| REGISTRY: ghcr.io | |
| # github.repository_owner preserves the owner's display case (e.g. | |
| # `IamCoder18`). GHCR resolves package lookups case-insensitively at the | |
| # storage layer, so `ghcr.io/IamCoder18/synapse-website` and | |
| # `ghcr.io/iamcoder18/synapse-website` point at the same package — we use | |
| # the lowercase spelling in the docker-compose files purely for | |
| # readability. | |
| IMAGE_NAME: ${{ github.repository_owner }}/synapse-website | |
| jobs: | |
| build: | |
| name: Build & push image | |
| runs-on: ubuntu-latest | |
| # Publish only on direct pushes to main or on v* tags. PRs run the | |
| # build-pr job (push: false, no cache-to) below. | |
| if: github.event_name != 'pull_request' | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Log in to GHCR | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Extract metadata | |
| id: meta | |
| uses: docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} | |
| tags: | | |
| type=ref,event=branch | |
| type=semver,pattern={{version}} | |
| type=semver,pattern={{major}}.{{minor}} | |
| type=sha,format=short | |
| type=raw,value=latest,enable={{is_default_branch}} | |
| - name: Build and push | |
| uses: docker/bake-action@v5 | |
| with: | |
| # `files` paths are resolved relative to the action's working | |
| # directory (the repo root after checkout). The bake target's | |
| # own `context` controls where the Dockerfile and source files | |
| # are read from. | |
| files: | | |
| website/docker-bake.hcl | |
| targets: synapse-website | |
| push: true | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-pr: | |
| name: Build (PR only) | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'pull_request' | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Build | |
| uses: docker/bake-action@v5 | |
| with: | |
| files: | | |
| website/docker-bake.hcl | |
| # Use the dedicated PR target, which omits `cache-to` because | |
| # fork PRs lack permission to write to the GHA cache. | |
| targets: synapse-website-pr | |
| push: false |