name: Build and Push Docker Image on: push: branches: [main] workflow_dispatch: jobs: build: # Runs on the forgerunner host: bundled Docker CLI + mounted /var/run/docker.sock. # The host builds with the legacy Docker builder (buildx/BuildKit is not installed # on the runner), so the Dockerfile avoids BuildKit-only features. runs-on: host steps: - name: Checkout uses: actions/checkout@v4 with: # Full history so `git rev-list --count HEAD` yields the true commit count # driving both the app version (v1.NNN) and the org.alwisp.version label. fetch-depth: 0 - name: Log in to Gitea Container Registry uses: docker/login-action@v3 with: registry: registry.alwisp.com username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_TOKEN }} - name: Build and Push run: | IMAGE="registry.alwisp.com/${{ gitea.repository }}" GIT_SHA="$(git rev-parse --short HEAD)" BUILD_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)" COMMIT_COUNT="$(git rev-list --count HEAD)" docker build \ --build-arg GIT_SHA="${GIT_SHA}" \ --build-arg BUILD_TIME="${BUILD_TIME}" \ --build-arg COMMIT_COUNT="${COMMIT_COUNT}" \ --label org.alwisp.git-sha="${{ gitea.sha }}" \ --label org.alwisp.version="v1.$((COMMIT_COUNT-1))" \ --label org.alwisp.repo="${{ gitea.repository }}" \ -t "${IMAGE}:latest" . docker push "${IMAGE}:latest" # Dangling-only prune: removes untagged leftovers from previous builds. Never # removes the tagged :latest or any image referenced by a running container. - name: Prune dangling images on host if: always() run: docker image prune -f 2>/dev/null || true - name: Trigger PORT redeploy if: success() run: | NAME="${{ gitea.repository }}"; NAME="${NAME##*/}" curl -fsS -X POST https://port.alwisp.com/hooks/gitea \ -H "X-Deploy-Token: ${{ secrets.WEBHOOK_SECRET }}" \ -H "Content-Type: application/json" \ -d "{\"container\":\"${NAME}\"}" || echo "PORT redeploy trigger failed (non-fatal)"