Stock caddy:2-alpine plus caddy-dns/desec, for ACME DNS-01 against zones hosted at deSEC (*.llm.aneur.in in cloud/cloud's llm stack). CI builds and checks the module on pull requests, and pushes :latest (keeping :previous) on main, weekly and by hand. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,44 @@
|
||||
name: Build
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
schedule:
|
||||
# Weekly, so new Caddy and caddy-dns/desec releases land without a commit.
|
||||
- cron: "17 4 * * 1"
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
build-and-push:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: docker:cli
|
||||
env:
|
||||
IMAGE: code.aneur.in/${{ gitea.repository }}
|
||||
steps:
|
||||
- name: Install Node (for checkout)
|
||||
run: apk add --no-cache nodejs
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Build
|
||||
run: docker build --pull --tag "$IMAGE:latest" .
|
||||
|
||||
- name: Check the deSEC module is built in
|
||||
run: docker run --rm "$IMAGE:latest" caddy list-modules | grep -x dns.providers.desec
|
||||
|
||||
- name: Log in to the container registry
|
||||
env:
|
||||
BUILD_API_TOKEN: ${{ secrets.BUILD_API_TOKEN }}
|
||||
run: echo "$BUILD_API_TOKEN" | docker login code.aneur.in -u "${{ gitea.actor }}" --password-stdin
|
||||
|
||||
- name: Promote current "latest" to "previous"
|
||||
run: |
|
||||
if docker buildx imagetools inspect "$IMAGE:latest" >/dev/null 2>&1; then
|
||||
docker buildx imagetools create -t "$IMAGE:previous" "$IMAGE:latest"
|
||||
else
|
||||
echo "No existing :latest to promote; skipping."
|
||||
fi
|
||||
|
||||
- name: Push "latest"
|
||||
run: docker push "$IMAGE:latest"
|
||||
@@ -0,0 +1,23 @@
|
||||
name: PR Checks
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
checks:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: docker:cli
|
||||
steps:
|
||||
- name: Install Node (for checkout)
|
||||
run: apk add --no-cache nodejs
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Build
|
||||
run: docker build --pull --tag caddy-desec-docker:check .
|
||||
|
||||
- name: Check the deSEC module is built in
|
||||
run: docker run --rm caddy-desec-docker:check caddy list-modules | grep -x dns.providers.desec
|
||||
@@ -0,0 +1,8 @@
|
||||
# Caddy with the caddy-dns/desec module, for ACME DNS-01 challenges against
|
||||
# zones hosted at deSEC. Otherwise the stock caddy:2-alpine image.
|
||||
|
||||
FROM caddy:2-builder AS builder
|
||||
RUN xcaddy build --with github.com/caddy-dns/desec
|
||||
|
||||
FROM caddy:2-alpine
|
||||
COPY --from=builder /usr/bin/caddy /usr/bin/caddy
|
||||
@@ -0,0 +1,30 @@
|
||||
# caddy-desec-docker
|
||||
|
||||
Stock [Caddy](https://caddyserver.com) plus the
|
||||
[caddy-dns/desec](https://github.com/caddy-dns/desec) module, so Caddy can
|
||||
get certificates by ACME DNS-01 against a zone hosted at
|
||||
[deSEC](https://desec.io). Published as
|
||||
`code.aneur.in/cloud/caddy-desec-docker:latest` (linux/amd64).
|
||||
|
||||
Used by the `llm` stack in [cloud/cloud](https://code.aneur.in/cloud/cloud)
|
||||
for `*.llm.aneur.in`:
|
||||
|
||||
```
|
||||
{
|
||||
acme_dns desec {
|
||||
token {env.DESEC_TOKEN}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## Builds
|
||||
|
||||
- **Push to `main`, weekly, or by hand** (`build.yml`): builds the image,
|
||||
checks the deSEC module is present, then pushes `:latest`, keeping the
|
||||
previous one as `:previous`. The weekly run picks up new Caddy and module
|
||||
releases without a commit.
|
||||
- **Pull requests** (`pr-checks.yml`): the same build and module check,
|
||||
without pushing.
|
||||
|
||||
The push uses the `BUILD_API_TOKEN` Actions secret, a Gitea token with
|
||||
package write access.
|
||||
Reference in New Issue
Block a user