diff --git a/.github/workflows/coderpush-image-export.yml b/.github/workflows/coderpush-image-export.yml new file mode 100644 index 00000000000..d0189b2074c --- /dev/null +++ b/.github/workflows/coderpush-image-export.yml @@ -0,0 +1,55 @@ +name: Export CoderPush release images + +on: + workflow_dispatch: + inputs: + release_sha: + description: Full main commit SHA whose image build has passed + required: true + type: string + +permissions: + contents: read + packages: read + +jobs: + export: + if: github.repository == 'CoderPush/multica' && github.ref == 'refs/heads/main' + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + with: + fetch-depth: 0 + - name: Validate release commit + env: + RELEASE_SHA: ${{ inputs.release_sha }} + run: | + [[ "$RELEASE_SHA" =~ ^[0-9a-f]{40}$ ]] + git merge-base --is-ancestor "$RELEASE_SHA" HEAD + - uses: docker/login-action@v3 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - name: Export existing images + env: + RELEASE_SHA: ${{ inputs.release_sha }} + run: | + backend="ghcr.io/coderpush/multica-backend:sha-$RELEASE_SHA" + frontend="ghcr.io/coderpush/multica-web:sha-$RELEASE_SHA" + docker pull "$backend" + docker pull "$frontend" + docker image inspect "$backend" "$frontend" --format '{{json .RepoDigests}}' > image-digests.txt + docker image inspect "$backend" "$frontend" --format '{{.Id}} {{index .Config.Labels "org.opencontainers.image.revision"}}' > image-identities.txt + docker save "$backend" "$frontend" | gzip > images.tar.gz + sha256sum images.tar.gz > images.tar.gz.sha256 + - uses: actions/upload-artifact@v4 + with: + name: coderpush-images-${{ inputs.release_sha }} + path: | + images.tar.gz + images.tar.gz.sha256 + image-digests.txt + image-identities.txt + retention-days: 3 + compression-level: 0