<<<<<<< HEAD # Build the Crucible image (D7 trigger standard): PRs/main build only; tag `v*` # publishes registry.westgate.pw/deployment/crucible:. Never a mutable tag. ||||||| f3211f0 # Build the Crucible image. PR-first (D7): PRs build only; push to main also # publishes registry.westgate.pw/deployment/crucible:. Never a mutable tag. ======= # Publish the immutable crucible: image on version tags. # PR/main test builds live in test-image.yml and never publish, so registry # packages are only generated for releases we intend to use (not on every merge). >>>>>>> main # # Daemonless: the host-mode runner has no container runtime, so the image is # built by Nix (`nix build .#image`, see flake.nix) and pushed with skopeo # straight from the OCI tarball. No `docker build`/`docker login` involved. name: build-image on: pull_request: push: <<<<<<< HEAD branches: [main] tags: ['v*'] ||||||| f3211f0 branches: [main] pull_request: ======= tags: ["v*"] >>>>>>> main env: REGISTRY: registry.westgate.pw IMAGE: deployment/crucible jobs: publish: runs-on: nix-docker steps: - uses: actions/checkout@v4 with: { fetch-depth: 0 } - name: Resolve tag id: tag run: echo "sha=$(git rev-parse --short=12 HEAD)" >> "$GITHUB_OUTPUT" - name: Build OCI image (daemonless) run: nix build .#image <<<<<<< HEAD # Publish only on a v* tag push. PRs and main pushes build but never push. ||||||| f3211f0 # Publish only on main (post-merge). PRs verify the build but never push. ======= >>>>>>> main - name: Publish image <<<<<<< HEAD if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') ||||||| f3211f0 if: github.event_name == 'push' && github.ref == 'refs/heads/main' ======= >>>>>>> main env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }} run: | nix shell nixpkgs#skopeo -c skopeo copy \ --dest-creds "${REGISTRY_USER}:${REGISTRY_PASSWORD}" \ docker-archive:result \ "docker://${REGISTRY}/${IMAGE}:${{ steps.tag.outputs.sha }}" - name: Emit release fragment run: | FRAG_REPO=sow-tools \ FRAG_SHA=${{ steps.tag.outputs.sha }} \ FRAG_ARTIFACT="${REGISTRY}/${IMAGE}:${{ steps.tag.outputs.sha }}" \ FRAG_URL="${REGISTRY}/${IMAGE}" \ FRAG_RUN_ID=${{ gitea.run_id }} \ bash scripts/emit-release-fragment.sh - uses: actions/upload-artifact@v3 with: { name: release-fragment, path: release-fragment.json }