# Build the Crucible image. PR-first (D7): PRs build only; push to main also # publishes registry.westgate.pw/sow/crucible:. Never a mutable tag. # # Daemonless: the host-mode runner has no container runtime, so the image is # built by Nix (`nix build .#image`, see flake.nix) and pushed with skopeo # straight from the OCI tarball. No `docker build`/`docker login` involved. name: build-image on: push: branches: [main] pull_request: env: REGISTRY: registry.westgate.pw IMAGE: sow/crucible jobs: build-image: runs-on: nix-docker steps: - uses: actions/checkout@v4 with: { fetch-depth: 0 } - name: Resolve tag id: tag run: echo "sha=$(git rev-parse --short=12 HEAD)" >> "$GITHUB_OUTPUT" - name: Build OCI image (daemonless) run: nix build .#image # Publish only on main (post-merge). PRs verify the build but never push. - name: Publish image if: github.event_name == 'push' && github.ref == 'refs/heads/main' env: REGISTRY_USER: ${{ secrets.REGISTRY_USER }} REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }} run: | nix shell nixpkgs#skopeo -c skopeo copy \ --dest-creds "${REGISTRY_USER}:${REGISTRY_PASSWORD}" \ docker-archive:result \ "docker://${REGISTRY}/${IMAGE}:${{ steps.tag.outputs.sha }}" - name: Emit release fragment run: | FRAG_REPO=sow-tools \ FRAG_SHA=${{ steps.tag.outputs.sha }} \ FRAG_ARTIFACT="${REGISTRY}/${IMAGE}:${{ steps.tag.outputs.sha }}" \ FRAG_URL="${REGISTRY}/${IMAGE}" \ FRAG_RUN_ID=${{ gitea.run_id }} \ bash scripts/emit-release-fragment.sh - uses: actions/upload-artifact@v3 with: { name: release-fragment, path: release-fragment.json }