Skip to content

Build and Push Docker Image #69

Build and Push Docker Image

Build and Push Docker Image #69

name: Build and Push Docker Image
on:
schedule:
# Runs at 00:00 UTC on the 1st and 15th of every month
- cron: '0 0 1,15 * *'
workflow_dispatch:
env:
ECR_REGISTRY: 351480950201.dkr.ecr.us-west-2.amazonaws.com
ECR_REPOSITORY: github-runner
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions:
contents: write # Changed from 'read' to allow dummy commits
packages: write
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set lowercase owner
run: echo "OWNER=${GITHUB_REPOSITORY_OWNER,,}" >> $GITHUB_ENV
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Authenticate via GitHub Actions OIDC (auth role)
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::351480950201:role/qv-internal-github-actions-auth-role
aws-region: us-west-2
- name: Chain into ECR push role with repository session tag
run: |
CREDS=$(aws sts assume-role \
--role-arn arn:aws:iam::351480950201:role/qv-internal-github-actions-ecr-gha-deploy-role \
--role-session-name github-runner-ecr-push \
--tags "Key=repository,Value=analyticsMD/github-runner")
KEY=$(echo "$CREDS" | jq -r .Credentials.AccessKeyId)
SECRET=$(echo "$CREDS" | jq -r .Credentials.SecretAccessKey)
TOKEN=$(echo "$CREDS" | jq -r .Credentials.SessionToken)
echo "::add-mask::$KEY"
echo "::add-mask::$SECRET"
echo "::add-mask::$TOKEN"
{
echo "AWS_ACCESS_KEY_ID=$KEY"
echo "AWS_SECRET_ACCESS_KEY=$SECRET"
echo "AWS_SESSION_TOKEN=$TOKEN"
} >> "$GITHUB_ENV"
- name: Login to Amazon ECR
uses: aws-actions/amazon-ecr-login@v2
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
platforms: linux/amd64
push: true
tags: |
ghcr.io/${{ env.OWNER }}/github-runner:latest
ghcr.io/${{ env.OWNER }}/github-runner:${{ github.sha }}
${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:latest
${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:${{ github.sha }}
- name: Send Success Slack notification
if: success()
uses: slackapi/slack-github-action@v1.24.0
with:
channel-id: 'C0830SADR0X' #devops-github-actions Slack Channel ID
payload: |
{
"text": "Docker Image Build Success",
"blocks": [
{
"type": "section",
"text": {
"type": "mrkdwn",
"text": "✅ *Docker Image Build Successful*\n*Repository:* ${{ github.repository }}\n*Image:* ${{ env.REGISTRY }}/${{ env.REPO }}:${{ github.sha }}"
}
}
]
}
env:
SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}
- name: Send Failure Slack notification
if: failure()
uses: slackapi/slack-github-action@v1.24.0
with:
channel-id: 'C0830SADR0X' #devops-github-actions Slack Channel ID
payload: |
{
"text": "Docker Image Build Failed",
"blocks": [
{
"type": "section",
"text": {
"type": "mrkdwn",
"text": "❌ *Docker Image Build Failed*\n*Repository:* ${{ github.repository }}\n*Workflow:* ${{ github.workflow }}\n*Error:* Build and push operation failed\n\n*Check the logs:* ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}\n<!channel>"
}
}
]
}
env:
SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}
# Resets GitHub's 60-day scheduled-workflow inactivity timer (public repos only).
# Commits via the REST Contents API so GitHub signs them (web-flow) and they pass
# the "commits must have verified signatures" ruleset on main; plain git commits
# from the runner are unsigned and get rejected. Non-fatal: keepalive must never
# mask a real build result (the snapshot workflow gates on this run's success).
- name: Keep workflow active
if: always() && github.event_name == 'schedule'
continue-on-error: true
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
CONTENT=$(date -u +"Last workflow run: %Y-%m-%dT%H:%M:%SZ")
SHA=$(gh api "repos/${{ github.repository }}/contents/.github/.workflow-keep-alive" --jq .sha 2>/dev/null || true)
gh api -X PUT "repos/${{ github.repository }}/contents/.github/.workflow-keep-alive" \
-f message="chore: keep workflow active [skip ci]" \
-f content="$(printf '%s' "$CONTENT" | base64 -w0)" \
${SHA:+-f sha="$SHA"} \
-f branch=main