Skip to content

Commit

Permalink
Switch publishing to GitHub Container Registry
Browse files Browse the repository at this point in the history
Identical to the work done in WikiWatershed/docker-taudem#6
  • Loading branch information
rajadain committed Jul 12, 2024
1 parent ff3f825 commit 7ac08b5
Showing 1 changed file with 47 additions and 30 deletions.
77 changes: 47 additions & 30 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,35 +1,52 @@
name: release

on:
push:
tags: "*"
push:
tags: "*"

env:
REGISTRY: ghcr.io
IMAGE_NAME: WikiWatershed/rwd

jobs:
release:
runs-on: ubuntu-latest
steps:
- name: Checkout repo
uses: actions/checkout@v4

- name: Set SHA_TAG
run: |
echo "SHA_TAG=`git rev-parse --short HEAD`" >> $GITHUB_ENV
- name: Setup Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Login to Quay
uses: docker/login-action@v3
with:
registry: quay.io
username: ${{ secrets.QUAY_USERNAME }}
password: ${{ secrets.QUAY_PASSWORD }}

- name: Build and push
uses: docker/build-push-action@v6
with:
push: true
tags: |
quay.io/wikiwatershed/rwd:${SHA_TAG}
quay.io/wikiwatershed/rwd:${{ github.ref_name }}
quay.io/wikiwatershed/rwd:latest
release:
runs-on: ubuntu-latest

permissions:
contents: read
packages: write
attestations: write
id-token: write

steps:
- name: Checkout repo
uses: actions/checkout@v4

- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}

- name: Build and push
id: push
uses: docker/build-push-action@v6
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

- name: Generate artifact attestation
uses: actions/attest-build-provenance@v1
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
subject-digest: ${{ steps.push.outputs.digest }}
push-to-registry: true

0 comments on commit 7ac08b5

Please sign in to comment.