2.7 KiB
action/image-build
Composite Gitea Action that builds a container image with buildx and optionally
runs a smoke test. Does not push — pair with action/image-push to publish.
Splitting build from push lets a PR workflow run image-build without push or
deploy side effects while main runs the full build → push → deploy chain. A
PR build that pulls a private base image still needs a registry token limited to
the read:package capability; public-base builds need no token.
Usage
- uses: actions/checkout@v4
- uses: https://code.fritzlab.net/action/image-build@v1
with:
image: code.fritzlab.net/fritzlab/chrony
token: ${{ secrets.PACKAGE_READ_TOKEN }} # read:package; omit for public bases
smoke-test: docker run --rm --entrypoint /usr/sbin/chronyd $IMAGE -v
The image is built and tagged as <image>:<github.run_number> in the runner's
local Docker daemon. Subsequent steps (e.g. action/image-push) can reference
the same tag. PACKAGE_READ_TOKEN is an example caller-chosen secret name; the
contract is the token's read:package capability.
Inputs
| Name | Required | Default | Description |
|---|---|---|---|
image |
yes | — | Full image name without tag (e.g. code.fritzlab.net/fritzlab/chrony). |
context |
no | . |
Docker build context. |
dockerfile |
no | Dockerfile (in context) |
Path to the Dockerfile, relative to the context (or absolute under $GITHUB_WORKSPACE). Use for monorepos where the build context is the repo root but the Dockerfile lives in a subdir, e.g. dockerfile: api/Dockerfile. |
build-args |
no | — | Multiline KEY=VALUE build args. Visible in docker history — never put secrets here. |
secrets |
no | — | Multiline id=VALUE BuildKit secrets (--secret). For tokens the build needs (e.g. a ci-bot token to go mod download a private module) that must not leak into layers. Reference with RUN --mount=type=secret,id=<id>. |
smoke-test |
no | — | Shell command run after build. $IMAGE is set to <image>:<run_number>. Non-zero exit fails the action. |
token |
no | — | Registry token with read:package capability. Required to pull a private base image; omit for public bases. |
Outputs
| Name | Description |
|---|---|
tag |
Numeric tag assigned (= github.run_number). |
Smoke test patterns
Override entrypoint for a binary that expects no args:
smoke-test: docker run --rm --entrypoint /usr/sbin/chronyd $IMAGE -v
Run a help command that returns non-zero:
smoke-test: docker run --rm $IMAGE --help || true
Multiple checks chained:
smoke-test: |
docker run --rm $IMAGE --version
docker run --rm --entrypoint /bin/sh $IMAGE -c 'test -x /usr/local/bin/myapp'