action/image-build

Composite Gitea Action that builds a container image with buildx and optionally runs a smoke test. Does not push — pair with action/image-push to publish.

Splitting build from push lets a PR workflow run image-build without push or deploy side effects while main runs the full build → push → deploy chain. A PR build that pulls a private base image still needs a registry token limited to the read:package capability; public-base builds need no token.

Usage

- uses: actions/checkout@v4
- uses: https://code.fritzlab.net/action/image-build@v1
  with:
    image: code.fritzlab.net/fritzlab/chrony
    token: ${{ secrets.PACKAGE_READ_TOKEN }} # read:package; omit for public bases
    smoke-test: docker run --rm --entrypoint /usr/sbin/chronyd $IMAGE -v

The image is built and tagged as <image>:<github.run_number> in the runner's local Docker daemon. Subsequent steps (e.g. action/image-push) can reference the same tag. PACKAGE_READ_TOKEN is an example caller-chosen secret name; the contract is the token's read:package capability.

Inputs

Name Required Default Description
image yes Full image name without tag (e.g. code.fritzlab.net/fritzlab/chrony).
context no . Docker build context.
dockerfile no Dockerfile (in context) Path to the Dockerfile, relative to the context (or absolute under $GITHUB_WORKSPACE). Use for monorepos where the build context is the repo root but the Dockerfile lives in a subdir, e.g. dockerfile: api/Dockerfile.
build-args no Multiline KEY=VALUE build args. Visible in docker history — never put secrets here.
secrets no Multiline id=VALUE BuildKit secrets (--secret). For tokens the build needs (e.g. a ci-bot token to go mod download a private module) that must not leak into layers. Reference with RUN --mount=type=secret,id=<id>.
smoke-test no Shell command run after build. $IMAGE is set to <image>:<run_number>. Non-zero exit fails the action.
token no Registry token with read:package capability. Required to pull a private base image; omit for public bases.

Outputs

Name Description
tag Numeric tag assigned (= github.run_number).

Smoke test patterns

Override entrypoint for a binary that expects no args:

smoke-test: docker run --rm --entrypoint /usr/sbin/chronyd $IMAGE -v

Run a help command that returns non-zero:

smoke-test: docker run --rm $IMAGE --help || true

Multiple checks chained:

smoke-test: |
  docker run --rm $IMAGE --version
  docker run --rm --entrypoint /bin/sh $IMAGE -c 'test -x /usr/local/bin/myapp'
S
Description
fritzlab composite action: image-build
Readme
85 KiB
Languages
Go 67.3%
Python 31.1%
Dockerfile 1.6%