Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions .github/workflows/coderpush-image-export.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: Export CoderPush release images

on:
workflow_dispatch:
inputs:
release_sha:
description: Full main commit SHA whose image build has passed
required: true
type: string

permissions:
contents: read
packages: read

jobs:
export:
if: github.repository == 'CoderPush/multica' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Validate release commit
env:
RELEASE_SHA: ${{ inputs.release_sha }}
run: |
[[ "$RELEASE_SHA" =~ ^[0-9a-f]{40}$ ]]
git merge-base --is-ancestor "$RELEASE_SHA" HEAD
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Export existing images
env:
RELEASE_SHA: ${{ inputs.release_sha }}
run: |
backend="ghcr.io/coderpush/multica-backend:sha-$RELEASE_SHA"
frontend="ghcr.io/coderpush/multica-web:sha-$RELEASE_SHA"
docker pull "$backend"
docker pull "$frontend"
Comment on lines +40 to +41

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Logic Error: The docker pull commands will fail silently if the images don't exist for the specified SHA. Add error handling to verify image existence or provide clear failure messages when images are not found in the registry.

Suggested change
docker pull "$backend"
docker pull "$frontend"
docker pull "$backend" || { echo "Error: Backend image not found for SHA $RELEASE_SHA"; exit 1; }
docker pull "$frontend" || { echo "Error: Frontend image not found for SHA $RELEASE_SHA"; exit 1; }

docker image inspect "$backend" "$frontend" --format '{{json .RepoDigests}}' > image-digests.txt
docker image inspect "$backend" "$frontend" --format '{{.Id}} {{index .Config.Labels "org.opencontainers.image.revision"}}' > image-identities.txt
docker save "$backend" "$frontend" | gzip > images.tar.gz
sha256sum images.tar.gz > images.tar.gz.sha256
- uses: actions/upload-artifact@v4
with:
name: coderpush-images-${{ inputs.release_sha }}
path: |
images.tar.gz
images.tar.gz.sha256
image-digests.txt
image-identities.txt
retention-days: 3
compression-level: 0
Loading