Repository navigation
Build and Push Docker Image #69
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and Push Docker Image | |
| on: | |
| schedule: | |
| # Runs at 00:00 UTC on the 1st and 15th of every month | |
| - cron: '0 0 1,15 * *' | |
| workflow_dispatch: | |
| env: | |
| ECR_REGISTRY: 351480950201.dkr.ecr.us-west-2.amazonaws.com | |
| ECR_REPOSITORY: github-runner | |
| jobs: | |
| build-and-push: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write # Changed from 'read' to allow dummy commits | |
| packages: write | |
| id-token: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set lowercase owner | |
| run: echo "OWNER=${GITHUB_REPOSITORY_OWNER,,}" >> $GITHUB_ENV | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Authenticate via GitHub Actions OIDC (auth role) | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: arn:aws:iam::351480950201:role/qv-internal-github-actions-auth-role | |
| aws-region: us-west-2 | |
| - name: Chain into ECR push role with repository session tag | |
| run: | | |
| CREDS=$(aws sts assume-role \ | |
| --role-arn arn:aws:iam::351480950201:role/qv-internal-github-actions-ecr-gha-deploy-role \ | |
| --role-session-name github-runner-ecr-push \ | |
| --tags "Key=repository,Value=analyticsMD/github-runner") | |
| KEY=$(echo "$CREDS" | jq -r .Credentials.AccessKeyId) | |
| SECRET=$(echo "$CREDS" | jq -r .Credentials.SecretAccessKey) | |
| TOKEN=$(echo "$CREDS" | jq -r .Credentials.SessionToken) | |
| echo "::add-mask::$KEY" | |
| echo "::add-mask::$SECRET" | |
| echo "::add-mask::$TOKEN" | |
| { | |
| echo "AWS_ACCESS_KEY_ID=$KEY" | |
| echo "AWS_SECRET_ACCESS_KEY=$SECRET" | |
| echo "AWS_SESSION_TOKEN=$TOKEN" | |
| } >> "$GITHUB_ENV" | |
| - name: Login to Amazon ECR | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Build and push | |
| uses: docker/build-push-action@v5 | |
| with: | |
| context: . | |
| platforms: linux/amd64 | |
| push: true | |
| tags: | | |
| ghcr.io/${{ env.OWNER }}/github-runner:latest | |
| ghcr.io/${{ env.OWNER }}/github-runner:${{ github.sha }} | |
| ${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:latest | |
| ${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:${{ github.sha }} | |
| - name: Send Success Slack notification | |
| if: success() | |
| uses: slackapi/slack-github-action@v1.24.0 | |
| with: | |
| channel-id: 'C0830SADR0X' #devops-github-actions Slack Channel ID | |
| payload: | | |
| { | |
| "text": "Docker Image Build Success", | |
| "blocks": [ | |
| { | |
| "type": "section", | |
| "text": { | |
| "type": "mrkdwn", | |
| "text": "✅ *Docker Image Build Successful*\n*Repository:* ${{ github.repository }}\n*Image:* ${{ env.REGISTRY }}/${{ env.REPO }}:${{ github.sha }}" | |
| } | |
| } | |
| ] | |
| } | |
| env: | |
| SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }} | |
| - name: Send Failure Slack notification | |
| if: failure() | |
| uses: slackapi/slack-github-action@v1.24.0 | |
| with: | |
| channel-id: 'C0830SADR0X' #devops-github-actions Slack Channel ID | |
| payload: | | |
| { | |
| "text": "Docker Image Build Failed", | |
| "blocks": [ | |
| { | |
| "type": "section", | |
| "text": { | |
| "type": "mrkdwn", | |
| "text": "❌ *Docker Image Build Failed*\n*Repository:* ${{ github.repository }}\n*Workflow:* ${{ github.workflow }}\n*Error:* Build and push operation failed\n\n*Check the logs:* ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}\n<!channel>" | |
| } | |
| } | |
| ] | |
| } | |
| env: | |
| SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }} | |
| # Resets GitHub's 60-day scheduled-workflow inactivity timer (public repos only). | |
| # Commits via the REST Contents API so GitHub signs them (web-flow) and they pass | |
| # the "commits must have verified signatures" ruleset on main; plain git commits | |
| # from the runner are unsigned and get rejected. Non-fatal: keepalive must never | |
| # mask a real build result (the snapshot workflow gates on this run's success). | |
| - name: Keep workflow active | |
| if: always() && github.event_name == 'schedule' | |
| continue-on-error: true | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| CONTENT=$(date -u +"Last workflow run: %Y-%m-%dT%H:%M:%SZ") | |
| SHA=$(gh api "repos/${{ github.repository }}/contents/.github/.workflow-keep-alive" --jq .sha 2>/dev/null || true) | |
| gh api -X PUT "repos/${{ github.repository }}/contents/.github/.workflow-keep-alive" \ | |
| -f message="chore: keep workflow active [skip ci]" \ | |
| -f content="$(printf '%s' "$CONTENT" | base64 -w0)" \ | |
| ${SHA:+-f sha="$SHA"} \ | |
| -f branch=main |