name: Release # Builds and pushes an image tagged to match the git tag that triggered this # run -- e.g. pushing tag "v1.2.3" produces code.aneur.in//:v1.2.3. # Separate from build.yml's "latest"/"previous" tracking on push to main. # This project's CI/CD scope is intentionally just test/build/push -- # deployment (including how a given tag actually gets deployed) is being # split into a separate project. # # Assumes tags are cut from commits already on main (and so already covered # by ci.yml's checks) -- this workflow doesn't run the test suite itself. # # Requires secrets.BUILD_API_TOKEN -- a personal access token # (write:package scope) from the pushing account, stored manually as a repo # secret. The auto-injected secrets.GITEA_TOKEN does NOT work for this: it # never grants package-registry access regardless of the workflow's own # `permissions:` block -- a known Gitea limitation, not a config mistake # (https://github.com/go-gitea/gitea/issues/23642). on: push: tags: ['*'] jobs: build-and-push: runs-on: ubuntu-latest # Assumes the runner forwards the host's Docker socket into job # containers -- see the matching note in build.yml if this can't reach # a daemon. container: image: docker:cli options: -v /var/run/docker.sock:/var/run/docker.sock steps: # actions/checkout is a JS action; docker:cli is Alpine-based and has # no node on PATH by default (same issue fixed in ci.yml). - name: Install Node run: apk add --no-cache nodejs - uses: actions/checkout@v4 - name: Log in to the container registry env: BUILD_API_TOKEN: ${{ secrets.BUILD_API_TOKEN }} run: echo "$BUILD_API_TOKEN" | docker login code.aneur.in -u "${{ gitea.actor }}" --password-stdin - name: Build and push the image run: | IMAGE="code.aneur.in/${{ gitea.repository }}:${{ gitea.ref_name }}" docker build -t "$IMAGE" . docker push "$IMAGE"