# SPDX-License-Identifier: AGPL-3.0-or-later name: build app-proxy self-hosted on: workflow_dispatch: inputs: build-version: description: "Explicit Fluxer CalVer build version (YYYY.MDD.MICRO, UTC HHMMSS without leading zeroes) to use instead of automatic UTC clock allocation" type: string required: false default: "" permissions: actions: read contents: write packages: write concurrency: group: publish-fluxer-app-proxy-self-hosted cancel-in-progress: false env: GHCR_OWNER: ${{ github.repository_owner }} jobs: approve: name: approve build release permissions: {} runs-on: ubuntu-24.04 environment: builds timeout-minutes: 5 steps: - name: approved run: echo "Build release approved." meta: name: resolve metadata needs: approve runs-on: ubuntu-24.04 timeout-minutes: 5 permissions: contents: read outputs: build_version: ${{ steps.vars.outputs.build_version }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 env: GIT_CONFIG_GLOBAL: ${{ runner.temp }}/gitconfig - name: Set up Rust toolchain (CI helpers) uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de with: toolchain: "1.98.1" - name: set variables id: vars run: >- tools/ci/run.sh build-app-proxy --step set_metadata --build-version "${{ inputs['build-version'] }}" dist: name: build the canonical asset tree needs: meta runs-on: ubuntu-24.04 timeout-minutes: 60 permissions: actions: read contents: read packages: write env: IMAGE_REPO: ghcr.io/${{ github.repository_owner }}/fluxer-app-proxy-self-hosted BUILD_VERSION: ${{ needs.meta.outputs.build_version }} PUBLIC_ASSET_BASE_URL: "" BUNDLE_LOCAL_ASSETS: "true" steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 env: GIT_CONFIG_GLOBAL: ${{ runner.temp }}/gitconfig - name: Set up Rust toolchain (CI helpers) uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de with: toolchain: "1.98.1" - name: prepare docker config run: >- tools/ci/run.sh build-app-proxy --step prepare_docker_config - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 - name: configure ghcr auth env: GHCR_USERNAME: ${{ github.actor }} GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: >- tools/ci/run.sh build-app-proxy --step configure_ghcr_auth - name: build the dist once and publish it as the canonical asset image env: CACHE_FROM: type=registry,ref=ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:buildcache-dist CACHE_TO: type=registry,ref=ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:buildcache-dist,mode=max,image-manifest=true,oci-mediatypes=true,ignore-error=true DOCKER_BUILD_SUMMARY: false DOCKER_BUILD_RECORD_UPLOAD: false run: >- tools/ci/run.sh build-app-proxy --step build_dist - name: generate asset manifest run: >- tools/ci/run.sh build-app-proxy --step generate_asset_manifest - name: verify every manifest asset ships in the image run: >- tools/ci/run.sh build-app-proxy --step verify_published_assets build: name: build ${{ matrix.platform }} needs: [meta, dist] runs-on: ${{ matrix.runner }} timeout-minutes: 75 permissions: actions: read contents: read packages: write strategy: fail-fast: false matrix: include: - platform: amd64 runner: ubuntu-24.04 - platform: arm64 runner: ubuntu-24.04-arm steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 env: GIT_CONFIG_GLOBAL: ${{ runner.temp }}/gitconfig - name: resolve source date id: source run: echo "date=$(TZ=UTC git log -1 --no-show-signature --pretty=%cd --date=format-local:%Y-%m-%dT%H:%M:%SZ)" >> "$GITHUB_OUTPUT" - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc with: context: . file: fluxer_app_proxy/Dockerfile push: true provenance: false platforms: linux/${{ matrix.platform }} tags: ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:${{ needs.meta.outputs.build_version }}-${{ matrix.platform }} build-args: | BUILD_VERSION=${{ needs.meta.outputs.build_version }} SOURCE_SHA=${{ github.sha }} SOURCE_DATE=${{ steps.source.outputs.date }} APP_ASSETS_REF=ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:${{ needs.meta.outputs.build_version }}-assets APP_ASSETS_PLATFORM=linux/amd64 cache-from: type=registry,ref=ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:buildcache-${{ matrix.platform }} cache-to: type=registry,ref=ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:buildcache-${{ matrix.platform }},mode=max,image-manifest=true,oci-mediatypes=true,ignore-error=true env: DOCKER_BUILD_SUMMARY: false DOCKER_BUILD_RECORD_UPLOAD: false merge: name: merge multi-arch manifest needs: [meta, build] runs-on: ubuntu-24.04 timeout-minutes: 20 permissions: contents: write packages: write steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 env: GIT_CONFIG_GLOBAL: ${{ runner.temp }}/gitconfig - name: Set up Rust toolchain (CI helpers) uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de with: toolchain: "1.98.1" - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: verify cross-architecture asset parity env: APP_PROXY_ASSETS_REF: ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:${{ needs.meta.outputs.build_version }}-assets APP_PROXY_AMD64_REF: ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:${{ needs.meta.outputs.build_version }}-amd64 APP_PROXY_ARM64_REF: ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted:${{ needs.meta.outputs.build_version }}-arm64 run: >- tools/ci/run.sh build-app-proxy --step verify_asset_parity - name: create and push multi-arch manifest env: IMAGE: ghcr.io/${{ env.GHCR_OWNER }}/fluxer-app-proxy-self-hosted VERSION: ${{ needs.meta.outputs.build_version }} run: | set -euo pipefail docker buildx imagetools create -t "${IMAGE}:${VERSION}" \ "${IMAGE}:${VERSION}-amd64" \ "${IMAGE}:${VERSION}-arm64" docker buildx imagetools inspect "${IMAGE}:${VERSION}" - name: Create token id: create-token uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 with: client-id: ${{ vars.FLUXER_CI_APP_ID }} private-key: ${{ secrets.FLUXER_CI_APP_KEY }} owner: fluxerapp repositories: fluxer permission-contents: write - name: Publish GitHub release env: GH_TOKEN: ${{ steps.create-token.outputs.token }} SOURCE_SHA: ${{ github.sha }} VERSION: ${{ needs.meta.outputs.build_version }} RELEASE_BASELINE_SHA: ${{ vars.RELEASE_BASELINE_SHA }} run: >- tools/ci/run.sh release publish --component fluxer-app-proxy-self-hosted --build-version "${VERSION}" --source-sha "${SOURCE_SHA}" --previous-sha "${RELEASE_BASELINE_SHA}" - name: Advance moving image tags env: VERSION: ${{ needs.meta.outputs.build_version }} run: >- tools/ci/run.sh image-set promote --component fluxer-app-proxy-self-hosted --build-version "${VERSION}" --registry "ghcr.io/${{ env.GHCR_OWNER }}" --moving-tags v1,latest