name: Publish Images on: push: branches: - main jobs: test: name: Build and Test runs-on: ubuntu-latest concurrency: group: ${{ github.workflow }}-main-${{ matrix.images.target }} cancel-in-progress: true permissions: contents: read deployments: write issues: write packages: write strategy: fail-fast: false matrix: images: - environment: Production-SLIM prefix: slim- target: slim - environment: Production prefix: "" target: standard timeout-minutes: 60 env: CONTAINER_IMAGE_ID: "ghcr.io/super-linter/super-linter:${{ matrix.images.prefix }}latest" CONTAINER_IMAGE_TARGET: "${{ matrix.images.target }}" steps: - name: Checkout Code uses: actions/checkout@v4 - name: Set build metadata run: | if [[ ${{ github.event_name }} == 'push' ]] || [[ ${{ github.event_name }} == 'merge_group' ]]; then BUILD_REVISION=${{ github.sha }} BUILD_VERSION=${{ github.sha }} elif [[ ${{ github.event_name }} == 'pull_request' ]]; then BUILD_REVISION=${{ github.event.pull_request.head.sha }} BUILD_VERSION=${{ github.event.pull_request.head.sha }} else echo "[ERROR] Event not supported when setting build revision and build version" exit 1 fi if [ -z "${BUILD_REVISION}" ]; then echo "[ERROR] BUILD_REVISION is empty" exit 1 fi if [ -z "${BUILD_VERSION}" ]; then echo "[ERROR] BUILD_VERSION is empty" exit 1 fi { echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" echo "BUILD_REVISION=${BUILD_REVISION}" echo "BUILD_VERSION=${BUILD_VERSION}" } >> "${GITHUB_ENV}" - name: Free Disk space shell: bash run: | sudo rm -rf /usr/local/lib/android sudo rm -rf /usr/share/dotnet - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Build Image uses: docker/build-push-action@v5 with: context: . file: ./Dockerfile build-args: | BUILD_DATE=${{ env.BUILD_DATE }} BUILD_REVISION=${{ env.BUILD_REVISION }} BUILD_VERSION=${{ env.BUILD_VERSION }} load: true push: false secrets: | GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }} tags: | ${{ env.CONTAINER_IMAGE_ID }} target: "${{ matrix.images.target }}" - name: Run Test Suite run: make test - name: Login to GHCR uses: docker/login-action@v3.0.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Start ${{ matrix.images.environment }} Deployment uses: bobheadxi/deployments@v1.4.0 id: deployment with: step: start token: ${{ secrets.GITHUB_TOKEN }} env: ${{ matrix.images.environment }} - name: Build and Push Image uses: docker/build-push-action@v5 with: context: . file: ./Dockerfile build-args: | BUILD_DATE=${{ env.BUILD_DATE }} BUILD_REVISION=${{ env.BUILD_REVISION }} BUILD_VERSION=${{ env.BUILD_VERSION }} cache-from: type=registry,ref=${{ env.CONTAINER_IMAGE_ID }} load: false push: true secrets: | GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }} tags: | ${{ env.CONTAINER_IMAGE_ID }} target: "${{ matrix.images.target }}" - name: Update ${{ matrix.images.environment }} Deployment uses: bobheadxi/deployments@v1.4.0 # We depend on the 'deployment' step outputs, so we can't run this step # if the 'deployment' step didn't run. This can happen if any step # before the 'deployment' step fails. That's why 'always()' is not # suitable here. if: steps.deployment.conclusion != 'cancelled' && steps.deployment.conclusion != 'skipped' with: step: finish token: ${{ secrets.GITHUB_TOKEN }} status: ${{ job.status }} deployment_id: ${{ steps.deployment.outputs.deployment_id }} env: ${{ steps.deployment.outputs.env }} env_url: https://github.com/super-linter/super-linter - name: Create Issue on Failure uses: actions/github-script@v7 if: failure() with: github-token: ${{secrets.GITHUB_TOKEN}} script: | const create = await github.rest.issues.create({ owner: context.repo.owner, repo: context.repo.repo, title: "Failed to deploy to production", body: "Automation has failed us!\nMore information can be found at:\n - ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}", assignees: [ "zkoppert", "Hanse00", "ferrarimarco" ] })