Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 44 additions & 27 deletions .github/workflows/build.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: Build Runner Image
name: Build Runner Images

on:
push:
Expand All @@ -14,8 +14,18 @@ on:

jobs:
build:
name: Build and Test
name: Build and Test (${{ matrix.distro }})
runs-on: ubuntu-latest
# Both distro families are built in parallel; a failure in one does not
# cancel the other.
strategy:
fail-fast: false
matrix:
include:
- distro: debian
image: scalr/runner
- distro: ubuntu
image: scalr/runner-ubuntu
steps:
- name: Checkout
uses: actions/checkout@v4
Expand All @@ -36,43 +46,50 @@ jobs:
files: |
docker-bake.hcl
versions.json
targets: ${{ matrix.distro }}
load: true
# Use GitHub Actions cache (type=gha) — scoped per target, lives in
# GitHub's per-repo cache backend, not the public Docker Hub repo.
set: |
*.platform=linux/amd64
full.tags=scalr/runner:sha-${{ github.sha }}
python39.tags=scalr/runner:sha-${{ github.sha }}-python39
slim.tags=scalr/runner:sha-${{ github.sha }}-slim
full.cache-from=type=gha,scope=full
full.cache-to=type=gha,scope=full,mode=max
python39.cache-from=type=gha,scope=python39
python39.cache-to=type=gha,scope=python39,mode=max
slim.cache-from=type=gha,scope=slim
slim.cache-to=type=gha,scope=slim,mode=max
${{ matrix.distro }}-full.tags=${{ matrix.image }}:sha-${{ github.sha }}
${{ matrix.distro }}-python39.tags=${{ matrix.image }}:sha-${{ github.sha }}-python39
${{ matrix.distro }}-slim.tags=${{ matrix.image }}:sha-${{ github.sha }}-slim
${{ matrix.distro }}-full.cache-from=type=gha,scope=${{ matrix.distro }}-full
${{ matrix.distro }}-full.cache-to=type=gha,scope=${{ matrix.distro }}-full,mode=max
${{ matrix.distro }}-python39.cache-from=type=gha,scope=${{ matrix.distro }}-python39
${{ matrix.distro }}-python39.cache-to=type=gha,scope=${{ matrix.distro }}-python39,mode=max
${{ matrix.distro }}-slim.cache-from=type=gha,scope=${{ matrix.distro }}-slim
${{ matrix.distro }}-slim.cache-to=type=gha,scope=${{ matrix.distro }}-slim,mode=max

- name: Test full image
env:
IMAGE: ${{ matrix.image }}:sha-${{ github.sha }}
run: |
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'gcloud version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'aws --version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'az --version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'kubectl version --client'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'scalr -version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'python --version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'pip --version'
docker run --rm scalr/runner:sha-${{ github.sha }} -xc 'pip install requests'
docker run --rm "$IMAGE" -xc 'gcloud version'
docker run --rm "$IMAGE" -xc 'aws --version'
docker run --rm "$IMAGE" -xc 'az --version'
docker run --rm "$IMAGE" -xc 'kubectl version --client'
docker run --rm "$IMAGE" -xc 'scalr -version'
docker run --rm "$IMAGE" -xc 'python --version'
docker run --rm "$IMAGE" -xc 'pip --version'
docker run --rm "$IMAGE" -xc 'pip install requests'

- name: Test python39 image
env:
IMAGE: ${{ matrix.image }}:sha-${{ github.sha }}-python39
run: |
docker run --rm scalr/runner:sha-${{ github.sha }}-python39 -xc 'python --version'
docker run --rm scalr/runner:sha-${{ github.sha }}-python39 -xc 'pip --version'
docker run --rm scalr/runner:sha-${{ github.sha }}-python39 -xc 'pip install requests'
docker run --rm "$IMAGE" -xc 'python --version'
docker run --rm "$IMAGE" -xc 'pip --version'
docker run --rm "$IMAGE" -xc 'pip install requests'

- name: Test slim image
env:
IMAGE: ${{ matrix.image }}:sha-${{ github.sha }}-slim
run: |
docker run --rm scalr/runner:sha-${{ github.sha }}-slim -xc 'git --version'
docker run --rm scalr/runner:sha-${{ github.sha }}-slim -xc 'curl --version'
docker run --rm scalr/runner:sha-${{ github.sha }}-slim -xc 'jq --version'
docker run --rm "$IMAGE" -xc 'git --version'
docker run --rm "$IMAGE" -xc 'curl --version'
docker run --rm "$IMAGE" -xc 'jq --version'
# Confirm python and cloud tools are absent.
docker run --rm scalr/runner:sha-${{ github.sha }}-slim -xc '! command -v python'
docker run --rm scalr/runner:sha-${{ github.sha }}-slim -xc '! command -v aws'
docker run --rm "$IMAGE" -xc '! command -v python'
docker run --rm "$IMAGE" -xc '! command -v aws'
55 changes: 34 additions & 21 deletions .github/workflows/build_and_release_gar.yaml
Original file line number Diff line number Diff line change
@@ -1,15 +1,16 @@
name: Build and Release Runner Image (EU dev GAR)
name: Build and Release Runner Images (EU dev GAR)

# Triggered when a PR carries the `build-gar-images` label. Pushes test
# builds of all three variants to the EU dev GAR mirror only — Docker
# Hub and the US production mirror are never touched here (production
# is reserved for the release.yaml workflow).
# builds of all three variants, for both distro families (Debian and
# Ubuntu), to the EU dev GAR mirror only — Docker Hub and the US
# production mirror are never touched here (production is reserved for
# the release-debian.yaml / release-ubuntu.yaml workflows).
#
# Tags are derived from the PR source branch, lower-cased and prefixed
# with `branch-` so they cannot collide with the semver release tags
# produced by release.yaml. Example: branch `0.2.0` → `branch-0.2.0`,
# not `0.2.0`. This prevents a PR from a maliciously-named branch from
# overwriting an existing release image.
# produced by the release workflows. Example: branch `0.2.0` →
# `branch-0.2.0`, not `0.2.0`. This prevents a PR from a maliciously-named
# branch from overwriting an existing release image.

on:
pull_request:
Expand All @@ -22,9 +23,19 @@ permissions:

jobs:
build:
name: Build and Push to GAR (EU dev)
name: Build and Push to GAR (EU dev, ${{ matrix.distro }})
if: contains(github.event.pull_request.labels.*.name, 'build-gar-images')
runs-on: ubuntu-latest
# Both distro families are built in parallel; a failure in one does not
# cancel the other.
strategy:
fail-fast: false
matrix:
include:
- distro: debian
repo: scalr/runner
- distro: ubuntu
repo: scalr/runner-ubuntu
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down Expand Up @@ -72,7 +83,7 @@ jobs:
# PR source branch → Docker tag. Lower-cased (downstream agents
# lower-case image refs), slashes → dashes (illegal in tags), and
# prefixed with `branch-` so the tag can never collide with a
# semver release tag pushed by release.yaml.
# semver release tag pushed by the release workflows.
- name: Resolve branch tag
id: branch
run: |
Expand All @@ -84,7 +95,7 @@ jobs:
- name: Compose GAR image path
id: gar
run: |
echo "image=${{ vars.EU_DEV_MIRROR_LOCATION }}-docker.pkg.dev/${{ vars.EU_DEV_GOOGLE_PROJECT }}/main/scalr/runner" | tee -a $GITHUB_OUTPUT
echo "image=${{ vars.EU_DEV_MIRROR_LOCATION }}-docker.pkg.dev/${{ vars.EU_DEV_GOOGLE_PROJECT }}/main/${{ matrix.repo }}" | tee -a $GITHUB_OUTPUT

- name: Build and push images
uses: docker/bake-action@v5
Expand All @@ -94,34 +105,36 @@ jobs:
files: |
docker-bake.hcl
versions.json
targets: ${{ matrix.distro }}
push: true
# Replace each target's tag list (`tags=` removes the Docker Hub
# default from docker-bake.hcl) so the build pushes only to the EU
# dev GAR mirror, which also holds the per-branch buildcache.
set: |
full.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}
python39.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}-python39
slim.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}-slim
full.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}
python39.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-python39
slim.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-slim
full.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }},mode=max
python39.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-python39,mode=max
slim.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-slim,mode=max
${{ matrix.distro }}-full.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}
${{ matrix.distro }}-python39.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}-python39
${{ matrix.distro }}-slim.tags=${{ steps.gar.outputs.image }}:${{ steps.branch.outputs.tag }}-slim
${{ matrix.distro }}-full.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}
${{ matrix.distro }}-python39.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-python39
${{ matrix.distro }}-slim.cache-from=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-slim
${{ matrix.distro }}-full.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }},mode=max
${{ matrix.distro }}-python39.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-python39,mode=max
${{ matrix.distro }}-slim.cache-to=type=registry,ref=${{ steps.gar.outputs.image }}:buildcache-${{ steps.branch.outputs.tag }}-slim,mode=max

- name: Report published images
env:
BRANCH: ${{ github.head_ref }}
DISTRO: ${{ matrix.distro }}
TAG: ${{ steps.branch.outputs.tag }}
IMG: ${{ steps.gar.outputs.image }}
run: |
echo "Published GAR (EU dev) images for branch ${BRANCH}"
echo "Published GAR (EU dev) ${DISTRO} images for branch ${BRANCH}"
echo ""
echo " ${IMG}:${TAG}"
echo " ${IMG}:${TAG}-python39"
echo " ${IMG}:${TAG}-slim"
{
echo "## Published runner images — branch \`${BRANCH}\`"
echo "## Published ${DISTRO} runner images — branch \`${BRANCH}\`"
echo ""
echo "**GAR — EU dev**"
echo ""
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,14 @@
name: Release Runner Image
name: Release Runner Image (Debian)

# Triggered by tags of the form `debian/<x.y.z>`, e.g. `debian/0.5.0`.
# The distro prefix is stripped before it is used as the image tag, so
# `debian/0.5.0` publishes `scalr/runner:0.5.0`. The Ubuntu family is
# released independently by release-ubuntu.yaml.

on:
push:
tags:
- "*.*.*"
- "debian/*.*.*"

permissions:
# Needed by the update_changelog job to git-push CHANGELOG.md back to main.
Expand Down Expand Up @@ -55,10 +60,12 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

# `refs/tags/debian/0.5.0` -> `0.5.0`
- name: Format Image Tag
id: image_tag
run: |
echo "tag=${GITHUB_REF#refs/tags/}" | tee -a $GITHUB_OUTPUT
ref="${GITHUB_REF#refs/tags/}"
echo "tag=${ref#debian/}" | tee -a $GITHUB_OUTPUT

# Two regional GAR mirrors — EU dev and US production.
- name: Compose GAR image paths
Expand All @@ -75,32 +82,33 @@ jobs:
files: |
docker-bake.hcl
versions.json
targets: debian
push: true
# Append both GAR region tags to each target so a single push writes
# to Docker Hub (declared in docker-bake.hcl) and both regional GAR
# mirrors. Cache uses GitHub Actions cache (per-repo, private) so
# nothing cache-related leaks into the public Docker Hub repo.
set: |
full.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}
full.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}
python39.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}-python39
python39.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}-python39
slim.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}-slim
slim.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}-slim
full.cache-from=type=gha,scope=full
full.cache-to=type=gha,scope=full,mode=max
python39.cache-from=type=gha,scope=python39
python39.cache-to=type=gha,scope=python39,mode=max
slim.cache-from=type=gha,scope=slim
slim.cache-to=type=gha,scope=slim,mode=max
debian-full.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}
debian-full.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}
debian-python39.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}-python39
debian-python39.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}-python39
debian-slim.tags+=${{ steps.gar.outputs.image_eu }}:${{ steps.image_tag.outputs.tag }}-slim
debian-slim.tags+=${{ steps.gar.outputs.image_us }}:${{ steps.image_tag.outputs.tag }}-slim
debian-full.cache-from=type=gha,scope=debian-full
debian-full.cache-to=type=gha,scope=debian-full,mode=max
debian-python39.cache-from=type=gha,scope=debian-python39
debian-python39.cache-to=type=gha,scope=debian-python39,mode=max
debian-slim.cache-from=type=gha,scope=debian-slim
debian-slim.cache-to=type=gha,scope=debian-slim,mode=max

- name: Report published images
env:
TAG: ${{ steps.image_tag.outputs.tag }}
IMG_EU: ${{ steps.gar.outputs.image_eu }}
IMG_US: ${{ steps.gar.outputs.image_us }}
run: |
echo "Published runner images for release ${TAG}"
echo "Published Debian runner images for release ${TAG}"
echo ""
echo "Docker Hub:"
echo " scalr/runner:${TAG}"
Expand All @@ -117,7 +125,7 @@ jobs:
echo " ${IMG_US}:${TAG}-python39"
echo " ${IMG_US}:${TAG}-slim"
{
echo "## Published runner images — \`${TAG}\`"
echo "## Published Debian runner images — \`${TAG}\`"
echo ""
echo "**Docker Hub**"
echo ""
Expand All @@ -136,36 +144,4 @@ jobs:
echo "- \`${IMG_US}:${TAG}\`"
echo "- \`${IMG_US}:${TAG}-python39\`"
echo "- \`${IMG_US}:${TAG}-slim\`"
} >> "$GITHUB_STEP_SUMMARY"

update_changelog:
name: Update Changelog
runs-on: ubuntu-latest
needs: build
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: main

- uses: ruby/setup-ruby@v1
with:
ruby-version: "3.3"

- name: Install Changelog Generator
run: gem install github_changelog_generator

- name: Update CHANGELOG.md
env:
CHANGELOG_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
github_changelog_generator -u Scalr -p runner --output CHANGELOG.md
git add CHANGELOG.md
if [ ! -n "$(git status -s)" ]; then
echo "NOTHING TO COMMIT"
else
git config user.name "${GITHUB_ACTOR}"
git config user.email "${GITHUB_ACTOR}@users.noreply.github.com"
git commit -m "Update CHANGELOG.md"
git push --no-verify
fi
} >> "$GITHUB_STEP_SUMMARY"
Loading
Loading