-
Notifications
You must be signed in to change notification settings - Fork 0
142 lines (135 loc) · 6.86 KB
/
Copy pathdocker.yml
File metadata and controls
142 lines (135 loc) · 6.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# Builds all four images, scans them, and publishes :edge.
#
# It publishes on purpose. The prior analysis copied a build-but-do-not-push precedent, but e2e.yml
# consumes GHCR images: with releases as the only publisher, the topology check could not run until
# after the release it exists to protect, and a nightly e2e would exercise the last release rather
# than current master. :edge is also the tag someone tracking the tip wants.
#
# amd64 only here. arm64 goes through QEMU and costs tens of minutes on a JVM image, which is why it
# belongs in release.yml and not on any path that runs per merge.
#
# **On a pull request it builds only, and that trigger is the point.** This was for a long time the
# only workflow that opens a Dockerfile, and it ran on master alone — so a PR changing nothing but a
# base image collected fourteen green checks from jobs that never read the file it changed, and the
# image was first built in the run that also publishes :edge. A node:22-alpine to node:26-alpine PR
# demonstrated it exactly; had that base been broken rather than merely premature, the checks would
# have looked identical. The path filter keeps the cost where the risk is — nothing here runs on a PR
# touching no Dockerfile. Login, scan, SARIF upload and push stay master-only, which is what the
# tracked design asked for: the Trivy scan runs with exit-code 0 and so gates nothing, and its findings
# are a statement about the published image, so uploading them per PR adds alerts nobody acts on. The
# PR run exists to answer one question — does this Dockerfile still build — and answers it in the only
# place that can, before the change is on master.
name: docker
on:
push:
branches: [master]
pull_request:
paths:
- '**/Dockerfile*'
- 'spire-ui/nginx/**'
- '.github/workflows/docker.yml'
workflow_dispatch:
permissions:
contents: read
packages: write
security-events: write
concurrency:
group: docker-${{ github.ref }}
cancel-in-progress: true
jobs:
images:
name: ${{ matrix.name }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- name: spire-gateway
context: .
dockerfile: Dockerfile
service: gateway
apkUpgrade: true
- name: spire-orchestrator
context: .
dockerfile: Dockerfile
service: orchestrator
apkUpgrade: true
- name: spire-review-worker
context: .
dockerfile: Dockerfile
service: review-worker
apkUpgrade: true
- name: spire-ui
context: ./spire-ui
dockerfile: ./spire-ui/Dockerfile
service: ''
apkUpgrade: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- if: github.event_name == 'push'
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: ${{ matrix.context }}
file: ${{ matrix.dockerfile }}
# Two lines, each empty for the entry it does not apply to; the action skips empty items.
#
# **APK_UPGRADE_BUST is a security control, not tidying.** `RUN apk --no-cache upgrade` has
# no input that changes, so with cache-from restoring it BuildKit re-used that layer on
# every build and the upgrade ran once — its only cache key being the base image, which is
# exactly the retag cadence the upgrade exists to not wait for. Run 33810550375 logged it
# CACHED for all three services while 102 Trivy alerts stood open on packages the live
# Alpine index had already fixed. github.run_id is unique per build, so the layer
# re-executes; the Dockerfile echoes the value because BuildKit keys a RUN on the args it
# actually references.
#
# Every image in this matrix consumes it today, so the flag looks redundant — it is not.
# An unconsumed build arg warns on every build, and a warning nobody can act on trains
# people past the ones they can, so an image added later must opt in rather than inherit.
# ApkUpgradeIsNotCachedTest asserts BOTH directions against the Dockerfiles themselves.
build-args: |
${{ matrix.service && format('SERVICE={0}', matrix.service) || '' }}
${{ matrix.apkUpgrade && format('APK_UPGRADE_BUST={0}', github.run_id) || '' }}
platforms: linux/amd64
load: true
tags: ghcr.io/artyomsv/${{ matrix.name }}:edge
cache-from: type=gha,scope=${{ matrix.name }}
# Cache writes from a PR ref land in a scope the master build never reads, so exporting there
# costs storage and buys nothing. Same conditional idiom as build-args above.
cache-to: ${{ github.event_name == 'push' && format('type=gha,scope={0},mode=max', matrix.name) || '' }}
# Report-only, and the reasoning is recorded rather than assumed: the residual HIGH/CRITICALs on
# a fully patched image are language-stdlib CVEs fixed only in unreleased toolchain versions — an
# advisory treadmill no bump can clear. Fixable module and OS CVEs are bumped promptly and
# triaged from the Security tab, which is what the SARIF upload is for.
- name: Scan
if: github.event_name == 'push'
# This action's tags are v-prefixed, so the trailing comment reads v0.36.0 rather than the
# 0.36.0 its own README uses. The comment is what Dependabot matches against; the SHA is
# what actually runs, which is why the distinction no longer breaks the job at setup.
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: ghcr.io/artyomsv/${{ matrix.name }}:edge
format: sarif
output: trivy-${{ matrix.name }}.sarif
exit-code: '0'
severity: HIGH,CRITICAL
- name: Report
if: github.event_name == 'push'
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
sarif_file: trivy-${{ matrix.name }}.sarif
category: trivy-${{ matrix.name }}
- name: Push
if: github.event_name == 'push'
run: |
short="${GITHUB_SHA::7}"
docker tag "ghcr.io/artyomsv/${{ matrix.name }}:edge" \
"ghcr.io/artyomsv/${{ matrix.name }}:sha-${short}"
docker push "ghcr.io/artyomsv/${{ matrix.name }}:edge"
docker push "ghcr.io/artyomsv/${{ matrix.name }}:sha-${short}"