Skip to content

Commit 2b93717

Browse files
committed
fix(docker): split push vs PR targets, drop redundant source
Two fixes: 1. The push and PR jobs were sharing the same bake target, so the PR job was also exporting cache via 'cache-to = type=gha,mode=max'. Fork PRs lack permission to write to the GHA cache, which would fail the required build check. Split the bake file into two targets: - synapse-website: full config including cache-to (push job) - synapse-website-pr: same minus cache-to (PR job) 2. The workflow passed 'source: website' to bake-action plus a relative file path 'docker-bake.hcl', but bake-action runs docker buildx from the action's working directory (the repo root) and does not change cwd when 'source' is set — 'source' only maps to --context. So 'docker-bake.hcl' resolved against the repo root and didn't exist. Drop 'source' from both jobs and use the full relative path 'website/docker-bake.hcl' in 'files'. Each target now sets its own context = 'website', so --context is still correct. Also dropped metadata-action's bake-file output from the bake inputs; tags and labels are already passed directly via the action's 'tags' / 'labels' inputs, so the second --file was redundant. Verified locally: docker buildx bake --file website/docker-bake.hcl --print synapse-website docker buildx bake --file website/docker-bake.hcl --print synapse-website-pr both produce the expected plans from the repo root.
1 parent 9818bfa commit 2b93717

2 files changed

Lines changed: 25 additions & 15 deletions

File tree

‎.github/workflows/docker.yml‎

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
name: Build & push image
2424
runs-on: ubuntu-latest
2525
# Publish only on direct pushes to main or on v* tags. PRs run the
26-
# build-pr job (push: false) below.
26+
# build-pr job (push: false, no cache-to) below.
2727
if: github.event_name != 'pull_request'
2828
permissions:
2929
contents: read
@@ -53,19 +53,16 @@ jobs:
5353
type=semver,pattern={{major}}.{{minor}}
5454
type=sha,format=short
5555
type=raw,value=latest,enable={{is_default_branch}}
56-
bake-target: synapse-website
5756
5857
- name: Build and push
5958
uses: docker/bake-action@v5
6059
with:
61-
# `source` is the build context that the bake target's
62-
# context="." resolves to. Bake definition file paths are
63-
# resolved relative to this directory, so `docker-bake.hcl`
64-
# (not `website/docker-bake.hcl`).
65-
source: website
60+
# `files` paths are resolved relative to the action's working
61+
# directory (the repo root after checkout). The bake target's
62+
# own `context` controls where the Dockerfile and source files
63+
# are read from.
6664
files: |
67-
docker-bake.hcl
68-
${{ steps.meta.outputs.bake-file }}
65+
website/docker-bake.hcl
6966
targets: synapse-website
7067
push: true
7168
tags: ${{ steps.meta.outputs.tags }}
@@ -87,8 +84,9 @@ jobs:
8784
- name: Build
8885
uses: docker/bake-action@v5
8986
with:
90-
source: website
9187
files: |
92-
docker-bake.hcl
93-
targets: synapse-website
88+
website/docker-bake.hcl
89+
# Use the dedicated PR target, which omits `cache-to` because
90+
# fork PRs lack permission to write to the GHA cache.
91+
targets: synapse-website-pr
9492
push: false

‎website/docker-bake.hcl‎

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,27 @@
11
# Build targets consumed by docker/bake-action (see .github/workflows/docker.yml).
2-
# Defining the build here keeps the Dockerfile, tags, cache config, and platform
3-
# declarations in one file under the website/ source tree.
2+
# Defining the build here keeps the Dockerfile, tags, cache config, and
3+
# platform declarations in one file under the website/ source tree.
4+
#
5+
# The PR build target omits `cache-to` because fork pull requests don't have
6+
# permission to write to the GHA cache; trying to export there fails the
7+
# required check.
48
group "default" {
59
targets = ["synapse-website"]
610
}
711

812
target "synapse-website" {
9-
context = "."
13+
context = "website"
1014
dockerfile = "Dockerfile"
1115
platforms = ["linux/amd64", "linux/arm64"]
1216
cache-from = ["type=gha"]
1317
cache-to = ["type=gha,mode=max"]
1418
tags = [""]
1519
}
20+
21+
target "synapse-website-pr" {
22+
context = "website"
23+
dockerfile = "Dockerfile"
24+
platforms = ["linux/amd64", "linux/arm64"]
25+
cache-from = ["type=gha"]
26+
tags = [""]
27+
}

0 commit comments

Comments
 (0)