Files
debian-base/.gitea/workflows/base-build.yml
fithwum edc3208c2e
Some checks failed
Build, Upload RootFS, and Push Docker Images, update changelog, update build info. / build-rootfs-per-version (push) Failing after 31s
Build, Upload RootFS, and Push Docker Images, update changelog, update build info. / generate-changelogs (push) Has been skipped
Build, Upload RootFS, and Push Docker Images, update changelog, update build info. / build-and-push-docker-images (push) Successful in 20s
Build, Upload RootFS, and Push Docker Images, update changelog, update build info. / generate-build-info (push) Successful in 20s
test
2025-07-10 07:55:18 -07:00

339 lines
12 KiB
YAML

name: Build, Upload RootFS, and Push Docker Images, update changelog, update build info.
on:
push:
branches:
- main
paths-ignore:
- '**/CHANGES.md'
- '**/build-info.json'
- '**/debian-*.tar.bz2'
- '/sha256sums.txt'
schedule:
- cron: '0 12 * * 0' # Sunday at noon UTC
env:
REPO_URL: ${{ secrets.REPO_URL }}
GIT_USERNAME: ${{ secrets.GIT_USERNAME }}
GIT_EMAIL: ${{ secrets.GIT_EMAIL }}
GIT_PASSWORD: ${{ secrets.GIT_PASSWORD }}
GIT_TOKEN: ${{ secrets.GIT_TOKEN }}
GIT_CREDENTIAL: ${{ secrets.GIT_TOKEN || secrets.GIT_PASSWORD }}
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
VERSIONS: "buster bullseye bookworm trixie"
VERSIONS_JSON: '["buster","bullseye","bookworm","trixie"]'
OUTPUT_DIR: ./output
jobs:
build-rootfs-per-version:
runs-on: vm-docker-build2
strategy:
matrix:
version: ${{ fromJson(env.VERSIONS_JSON) }}
outputs:
archive_changed: ${{ steps.check_changed.outputs.archive_changed }}
env:
VERSION: ${{ matrix.version }}
steps:
- name: Checkout source
uses: actions/checkout@v3
- name: Create output directory
run: mkdir -p ./output
- name: Build Debian ${{ env.VERSION }} rootfs
run: |
echo "[INFO] Building $VERSION..."
volume_name="build_output_$VERSION"
docker volume create "$volume_name"
docker build --build-arg VERSION=$VERSION -t fithwum/debian-$VERSION-base .
docker run --rm --privileged \
-v "$volume_name:/output" \
-e VERSION="$VERSION" \
fithwum/debian-$VERSION-base \
bash -c "/scripts/bootstrap-rootfs.sh \"$VERSION\""
container_id=$(docker create -v "$volume_name:/output" debian)
mkdir -p ./output/$VERSION
docker cp "$container_id:/output/$VERSION/debian-$VERSION.tar.bz2" ./output/$VERSION/
docker rm "$container_id"
- name: Clone upload repo
run: |
GIT_CREDENTIAL="${{ secrets.GIT_TOKEN || secrets.GIT_PASSWORD }}"
git clone --depth=1 "https://${{ env.GIT_USERNAME }}:${GIT_CREDENTIAL}@gitea.fithwum.tech/fithwum/debian-base.git" upload-repo
- name: Check if archive changed
id: check_changed
run: |
mkdir -p upload-repo/${VERSION}
new="./output/${VERSION}/debian-${VERSION}.tar.bz2"
old="upload-repo/${VERSION}/debian-${VERSION}.tar.bz2"
cp "$new" "$old"
checksum=$(sha256sum "$new" | awk '{print $1}')
echo "$checksum ${VERSION}/debian-${VERSION}.tar.bz2" >> upload-repo/sha256sums.txt
cd upload-repo
git config user.name "${{ env.GIT_USERNAME }}"
git config user.email "${{ env.GIT_EMAIL }}"
git add ${VERSION}/debian-${VERSION}.tar.bz2 sha256sums.txt || true
if git diff --cached --quiet; then
echo "[INFO] No changes to commit."
echo "archive_changed=false" >> $GITHUB_OUTPUT
else
git commit -m "Update rootfs for $VERSION"
git push
echo "archive_changed=true" >> $GITHUB_OUTPUT
fi
build-and-push-docker-images:
needs: build-rootfs-per-version
if: always()
runs-on: doc-docker-build
steps:
- name: Checkout source
uses: actions/checkout@v3
- name: Wait for archives to appear in upload repo
run: |
echo "[INFO] Waiting for archives to appear in upload-repo..."
mkdir -p temp-check
cd temp-check
# Retry loop for cloning the upload-repo
for i in {1..10}; do
echo "[INFO] Attempt $i: Cloning upload-repo..."
if git clone --depth=1 "https://${{ secrets.GIT_USERNAME }}:${{ secrets.GIT_TOKEN }}@gitea.fithwum.tech/fithwum/debian-base.git"; then
break
fi
echo "[WARN] Clone failed. Retrying in 10 seconds..."
sleep 10
done
if [ ! -d "debian-base" ]; then
echo "[ERROR] Failed to clone upload-repo after retries."
exit 1
fi
cd debian-base
# Wait for all versions to show up
missing_versions=()
for version in $VERSIONS; do
found=0
for i in {1..30}; do
if [[ -f "$version/debian-$version.tar.bz2" ]]; then
found=1
break
else
echo "[WAIT] $version not ready yet, sleeping 10s..."
sleep 10
fi
done
if [[ $found -eq 0 ]]; then
missing_versions+=("$version")
fi
if [[ ${#missing_versions[@]} -gt 0 ]]; then
echo "[ERROR] Missing archives for: ${missing_versions[*]}"
exit 1
fi
done
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Gitea Registry
run: echo "${{ secrets.DOCKER_PASSWORD }}" | docker login gitea.fithwum.tech -u "${{ secrets.DOCKER_USERNAME }}" --password-stdin
- name: Build and push Docker images
run: |
IMAGE_REGISTRY=gitea.fithwum.tech
IMAGE_ORG=fithwum
IMAGE_REPO=debian-base
for TAG in $VERSIONS; do
FULL_IMAGE="${IMAGE_REGISTRY}/${IMAGE_ORG}/${IMAGE_REPO}:${TAG}"
echo "[INFO] Building and pushing $FULL_IMAGE"
docker buildx build --platform linux/amd64 --push -t "$FULL_IMAGE" "./$TAG"
done
generate-changelogs:
needs: build-rootfs-per-version
runs-on: doc-docker-build
steps:
- name: Checkout source
uses: actions/checkout@v3
- name: Create temporary changelog workspace
run: mkdir changelogs
- name: Clone upload repo
run: |
GIT_CREDENTIAL="${{ secrets.GIT_TOKEN || secrets.GIT_PASSWORD }}"
git clone --depth=3 "https://${{ env.GIT_USERNAME }}:${GIT_CREDENTIAL}@gitea.fithwum.tech/fithwum/debian-base.git" upload-repo
- name: Generate changelogs from git log
run: |
for version in $VERSIONS; do
echo "[INFO] Generating changelog for $version"
changelog="changelogs/$version/CHANGES.md"
mkdir -p "$(dirname "$changelog")"
echo -e "## $(date -u +'%Y-%m-%dT%H:%M:%SZ')\n" >> "$changelog"
git log -n 3 --pretty=format:"- %h %ad %s (%an)" --date=short >> "$changelog"
done
- name: Copy generated changelogs into repo
run: |
for version in $VERSIONS; do
mkdir -p "upload-repo/$version"
cp "changelogs/$version/CHANGES.md" "upload-repo/$version/CHANGES.md"
done
- name: Commit and push changelogs if changed
run: |
cd upload-repo
git config user.name "${{ env.GIT_USERNAME }}"
git config user.email "${{ env.GIT_EMAIL }}"
if git status --porcelain | grep .; then
git add */CHANGES.md
git commit -m "Update changelogs on $(date -u +'%Y-%m-%dT%H:%M:%SZ')" --no-verify
git push
else
echo "[INFO] No changelog changes to commit."
fi
generate-build-info:
needs: build-and-push-docker-images
runs-on: doc-docker-build
steps:
- name: Checkout source
uses: actions/checkout@v3
- name: Prepare temporary build-info workspace
run: mkdir -p buildinfo
- name: Clone upload repo
run: |
GIT_CREDENTIAL="${{ secrets.GIT_TOKEN || secrets.GIT_PASSWORD }}"
git clone --depth=1 "https://${{ env.GIT_USERNAME }}:${GIT_CREDENTIAL}@gitea.fithwum.tech/fithwum/debian-base.git" upload-repo
- name: Copy sha256sums.txt
run: |
if [[ -f upload-repo/sha256sums.txt ]]; then
cp upload-repo/sha256sums.txt buildinfo/
else
echo "[ERROR] sha256sums.txt missing in upload-repo!"
exit 1
fi
- name: Generate build-info.json files
run: |
human_size() {
local b=$1
local d=''
local s=0
local S=(B KB MB GB TB)
while ((b >= 1024 && s < ${#S[@]}-1)); do
d=$((b % 1024))
b=$((b / 1024))
s=$((s + 1))
done
printf "%s%s\n" "$b" "${S[$s]}"
}
cd buildinfo
for version in $VERSIONS; do
echo "[INFO] Generating build-info.json for $version"
mkdir -p "$version"
infofile="$version/build-info.json"
image="gitea.fithwum.tech/fithwum/debian-base:$version"
# Pull image before inspecting to ensure metadata is available
if ! docker pull "$image"; then
echo "[WARN] Failed to pull $image — setting fields to 'unknown/0'"
digest="unknown"
size_bytes=0
else
digest=$(docker inspect --format='{{if .RepoDigests}}{{index .RepoDigests 0}}{{else}}unknown{{end}}' "$image" 2>/dev/null || echo "unknown")
size_bytes=$(docker image inspect "$image" --format='{{.Size}}' 2>/dev/null || echo "0")
size_bytes=${size_bytes//[^0-9]/}
if [[ -z "$size_bytes" ]]; then size_bytes=0; fi
fi
size_human=$(human_size "$size_bytes")
# Load SHA256 from file if available
TARBALL_NAME="debian-$version.tar.bz2"
SHA256_LINE=$(grep -F "$TARBALL_NAME" sha256sums.txt || true)
if [[ -z "$SHA256_LINE" ]]; then
echo "[WARN] SHA256 for $TARBALL_NAME not found!"
SHA256="unknown"
else
SHA256=$(echo "$SHA256_LINE" | awk '{print $1}')
echo "[INFO] SHA256 for $TARBALL_NAME: $SHA256"
fi
jq -n \
--arg version "$version" \
--arg commit "$(git rev-parse HEAD)" \
--arg build_time "$(date -u +'%Y-%m-%dT%H:%M:%SZ')" \
--arg image_tag "$image" \
--arg digest "$digest" \
--arg image_size "$size_human" \
--argjson image_size_bytes "$size_bytes" \
--arg sha256 "$SHA256" \
'{
version: $version,
commit: $commit,
build_time: $build_time,
image_tag: $image_tag,
digest: $digest,
image_size: $image_size,
image_size_bytes: $image_size_bytes,
rootfs_sha256: $sha256
}' > "$infofile"
done
- name: Clone upload repo
run: |
rm -rf upload-repo
GIT_CREDENTIAL="${{ secrets.GIT_TOKEN || secrets.GIT_PASSWORD }}"
git clone --depth=1 "https://${{ env.GIT_USERNAME }}:${GIT_CREDENTIAL}@gitea.fithwum.tech/fithwum/debian-base.git" upload-repo
- name: Copy build-info.json into repo
run: |
for version in $VERSIONS; do
mkdir -p "upload-repo/$version"
cp "buildinfo/$version/build-info.json" "upload-repo/$version/build-info.json"
done
- name: Commit and push build-info if changed
run: |
cd upload-repo
git config --global user.name "${{ env.GIT_USERNAME }}"
git config --global user.email "${{ env.GIT_EMAIL }}"
if git status --porcelain | grep .; then
git add */build-info.json
git commit -m "Update build-info on $(date -u +'%Y-%m-%dT%H:%M:%SZ')"
git push
for version in $VERSIONS; do
TAG="build-$version"
git tag -d "$TAG" 2>/dev/null || true
git tag "$TAG"
git push origin "$TAG" --force
done
else
echo "[INFO] No build-info changes to commit."
fi