fix gitea backend: use full GitHub URLs for all action refs
Gitea Actions resolves short refs (e.g. actions/checkout@v4) against the local Gitea instance, failing with "user redirect does not exist". All action uses: now use full URLs: https://github.com/actions/checkout@v4 https://github.com/astral-sh/setup-uv@v4 https://github.com/docker/build-push-action@v6 etc.
This commit is contained in:
@@ -13,10 +13,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up uv
|
- name: Set up uv
|
||||||
uses: astral-sh/setup-uv@v4
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
|
|||||||
@@ -12,13 +12,13 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Log in to container registry
|
- name: Log in to container registry
|
||||||
uses: docker/login-action@v3
|
uses: https://github.com/docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: gitea.homelab.fhirworx.io
|
registry: gitea.homelab.fhirworx.io
|
||||||
username: ${{ secrets.REGISTRY_USER }}
|
username: ${{ secrets.REGISTRY_USER }}
|
||||||
@@ -28,7 +28,7 @@ jobs:
|
|||||||
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
- name: Build notebooks
|
- name: Build notebooks
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
file: notebooks/Dockerfile
|
file: notebooks/Dockerfile
|
||||||
@@ -36,7 +36,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
|
||||||
|
|
||||||
- name: Build zotero
|
- name: Build zotero
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: zotero/
|
context: zotero/
|
||||||
file: zotero/Dockerfile
|
file: zotero/Dockerfile
|
||||||
@@ -44,7 +44,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
|
||||||
|
|
||||||
- name: Build docs
|
- name: Build docs
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docs/Dockerfile
|
file: docs/Dockerfile
|
||||||
@@ -52,7 +52,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
|
||||||
|
|
||||||
- name: Build api
|
- name: Build api
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: api/Dockerfile
|
file: api/Dockerfile
|
||||||
@@ -60,7 +60,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
|
||||||
|
|
||||||
- name: Build mc
|
- name: Build mc
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
file: rustfs/Dockerfile.mc
|
file: rustfs/Dockerfile.mc
|
||||||
@@ -72,13 +72,13 @@ jobs:
|
|||||||
needs: build
|
needs: build
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Compute short SHA
|
- name: Compute short SHA
|
||||||
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
- name: Scan notebooks
|
- name: Scan notebooks
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -87,7 +87,7 @@ jobs:
|
|||||||
output: notebooks-scan.json
|
output: notebooks-scan.json
|
||||||
|
|
||||||
- name: Scan zotero
|
- name: Scan zotero
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -96,7 +96,7 @@ jobs:
|
|||||||
output: zotero-scan.json
|
output: zotero-scan.json
|
||||||
|
|
||||||
- name: Scan docs
|
- name: Scan docs
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -105,7 +105,7 @@ jobs:
|
|||||||
output: docs-scan.json
|
output: docs-scan.json
|
||||||
|
|
||||||
- name: Scan api
|
- name: Scan api
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -114,7 +114,7 @@ jobs:
|
|||||||
output: api-scan.json
|
output: api-scan.json
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans
|
name: trivy-scans
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -124,15 +124,15 @@ jobs:
|
|||||||
needs: scan
|
needs: scan
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up uv
|
- name: Set up uv
|
||||||
uses: astral-sh/setup-uv@v4
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans
|
name: trivy-scans
|
||||||
|
|
||||||
|
|||||||
@@ -13,20 +13,20 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Log in to container registry
|
- name: Log in to container registry
|
||||||
uses: docker/login-action@v3
|
uses: https://github.com/docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: gitea.homelab.fhirworx.io
|
registry: gitea.homelab.fhirworx.io
|
||||||
username: ${{ secrets.REGISTRY_USER }}
|
username: ${{ secrets.REGISTRY_USER }}
|
||||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
|
|
||||||
- name: Build notebooks
|
- name: Build notebooks
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
file: notebooks/Dockerfile
|
file: notebooks/Dockerfile
|
||||||
@@ -35,7 +35,7 @@ jobs:
|
|||||||
no-cache: true
|
no-cache: true
|
||||||
|
|
||||||
- name: Build zotero
|
- name: Build zotero
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: zotero/
|
context: zotero/
|
||||||
file: zotero/Dockerfile
|
file: zotero/Dockerfile
|
||||||
@@ -44,7 +44,7 @@ jobs:
|
|||||||
no-cache: true
|
no-cache: true
|
||||||
|
|
||||||
- name: Build docs
|
- name: Build docs
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docs/Dockerfile
|
file: docs/Dockerfile
|
||||||
@@ -53,7 +53,7 @@ jobs:
|
|||||||
no-cache: true
|
no-cache: true
|
||||||
|
|
||||||
- name: Build api
|
- name: Build api
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: api/Dockerfile
|
file: api/Dockerfile
|
||||||
@@ -62,7 +62,7 @@ jobs:
|
|||||||
no-cache: true
|
no-cache: true
|
||||||
|
|
||||||
- name: Build mc
|
- name: Build mc
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
file: rustfs/Dockerfile.mc
|
file: rustfs/Dockerfile.mc
|
||||||
@@ -75,10 +75,10 @@ jobs:
|
|||||||
needs: build
|
needs: build
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Scan notebooks
|
- name: Scan notebooks
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:hardened
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:hardened
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -87,7 +87,7 @@ jobs:
|
|||||||
output: notebooks-scan.json
|
output: notebooks-scan.json
|
||||||
|
|
||||||
- name: Scan zotero
|
- name: Scan zotero
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:hardened
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:hardened
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -96,7 +96,7 @@ jobs:
|
|||||||
output: zotero-scan.json
|
output: zotero-scan.json
|
||||||
|
|
||||||
- name: Scan docs
|
- name: Scan docs
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:hardened
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:hardened
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -105,7 +105,7 @@ jobs:
|
|||||||
output: docs-scan.json
|
output: docs-scan.json
|
||||||
|
|
||||||
- name: Scan api
|
- name: Scan api
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:hardened
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:hardened
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -114,7 +114,7 @@ jobs:
|
|||||||
output: api-scan.json
|
output: api-scan.json
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-harden
|
name: trivy-scans-harden
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -124,15 +124,15 @@ jobs:
|
|||||||
needs: scan
|
needs: scan
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up uv
|
- name: Set up uv
|
||||||
uses: astral-sh/setup-uv@v4
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-harden
|
name: trivy-scans-harden
|
||||||
|
|
||||||
|
|||||||
@@ -28,18 +28,18 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Hadolint notebooks
|
- name: Hadolint notebooks
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: notebooks/Dockerfile
|
dockerfile: notebooks/Dockerfile
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build notebooks
|
- name: Build notebooks
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
file: notebooks/Dockerfile
|
file: notebooks/Dockerfile
|
||||||
@@ -51,18 +51,18 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Hadolint zotero
|
- name: Hadolint zotero
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: zotero/Dockerfile
|
dockerfile: zotero/Dockerfile
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build zotero
|
- name: Build zotero
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: zotero/
|
context: zotero/
|
||||||
file: zotero/Dockerfile
|
file: zotero/Dockerfile
|
||||||
@@ -74,18 +74,18 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Hadolint docs
|
- name: Hadolint docs
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: docs/Dockerfile
|
dockerfile: docs/Dockerfile
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build docs
|
- name: Build docs
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docs/Dockerfile
|
file: docs/Dockerfile
|
||||||
@@ -97,18 +97,18 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Hadolint api
|
- name: Hadolint api
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: api/Dockerfile
|
dockerfile: api/Dockerfile
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build api
|
- name: Build api
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: api/Dockerfile
|
file: api/Dockerfile
|
||||||
@@ -120,18 +120,18 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Hadolint mc
|
- name: Hadolint mc
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: rustfs/Dockerfile.mc
|
dockerfile: rustfs/Dockerfile.mc
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Build mc
|
- name: Build mc
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
file: rustfs/Dockerfile.mc
|
file: rustfs/Dockerfile.mc
|
||||||
|
|||||||
@@ -11,13 +11,13 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
uses: https://github.com/docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: Log in to container registry
|
- name: Log in to container registry
|
||||||
uses: docker/login-action@v3
|
uses: https://github.com/docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: gitea.homelab.fhirworx.io
|
registry: gitea.homelab.fhirworx.io
|
||||||
username: ${{ secrets.REGISTRY_USER }}
|
username: ${{ secrets.REGISTRY_USER }}
|
||||||
@@ -27,7 +27,7 @@ jobs:
|
|||||||
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
- name: Build notebooks
|
- name: Build notebooks
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: notebooks/
|
context: notebooks/
|
||||||
file: notebooks/Dockerfile
|
file: notebooks/Dockerfile
|
||||||
@@ -35,7 +35,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
|
||||||
|
|
||||||
- name: Build zotero
|
- name: Build zotero
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: zotero/
|
context: zotero/
|
||||||
file: zotero/Dockerfile
|
file: zotero/Dockerfile
|
||||||
@@ -43,7 +43,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
|
||||||
|
|
||||||
- name: Build docs
|
- name: Build docs
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docs/Dockerfile
|
file: docs/Dockerfile
|
||||||
@@ -51,7 +51,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
|
||||||
|
|
||||||
- name: Build api
|
- name: Build api
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: api/Dockerfile
|
file: api/Dockerfile
|
||||||
@@ -59,7 +59,7 @@ jobs:
|
|||||||
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
|
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
|
||||||
|
|
||||||
- name: Build mc
|
- name: Build mc
|
||||||
uses: docker/build-push-action@v6
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: rustfs/
|
context: rustfs/
|
||||||
file: rustfs/Dockerfile.mc
|
file: rustfs/Dockerfile.mc
|
||||||
@@ -71,13 +71,13 @@ jobs:
|
|||||||
needs: build
|
needs: build
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Compute short SHA
|
- name: Compute short SHA
|
||||||
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
- name: Scan notebooks
|
- name: Scan notebooks
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -86,7 +86,7 @@ jobs:
|
|||||||
output: notebooks-scan.json
|
output: notebooks-scan.json
|
||||||
|
|
||||||
- name: Scan zotero
|
- name: Scan zotero
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -95,7 +95,7 @@ jobs:
|
|||||||
output: zotero-scan.json
|
output: zotero-scan.json
|
||||||
|
|
||||||
- name: Scan docs
|
- name: Scan docs
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -104,7 +104,7 @@ jobs:
|
|||||||
output: docs-scan.json
|
output: docs-scan.json
|
||||||
|
|
||||||
- name: Scan api
|
- name: Scan api
|
||||||
uses: aquasecurity/trivy-action@master
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
with:
|
with:
|
||||||
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
|
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
|
||||||
severity: HIGH,CRITICAL
|
severity: HIGH,CRITICAL
|
||||||
@@ -113,7 +113,7 @@ jobs:
|
|||||||
output: api-scan.json
|
output: api-scan.json
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-rebuild
|
name: trivy-scans-rebuild
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -123,15 +123,15 @@ jobs:
|
|||||||
needs: scan
|
needs: scan
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up uv
|
- name: Set up uv
|
||||||
uses: astral-sh/setup-uv@v4
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-rebuild
|
name: trivy-scans-rebuild
|
||||||
|
|
||||||
|
|||||||
@@ -12,10 +12,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up uv
|
- name: Set up uv
|
||||||
uses: astral-sh/setup-uv@v4
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
@@ -23,7 +23,7 @@ jobs:
|
|||||||
run: uv build --out-dir dist/
|
run: uv build --out-dir dist/
|
||||||
|
|
||||||
- name: Create release
|
- name: Create release
|
||||||
uses: softprops/action-gh-release@v2
|
uses: https://github.com/softprops/action-gh-release@v2
|
||||||
with:
|
with:
|
||||||
files: |
|
files: |
|
||||||
dist/*.whl
|
dist/*.whl
|
||||||
|
|||||||
@@ -12,13 +12,96 @@ from __future__ import annotations
|
|||||||
|
|
||||||
from backends.github import (
|
from backends.github import (
|
||||||
_HEADER,
|
_HEADER,
|
||||||
_build_push_step,
|
|
||||||
_checkout_step,
|
|
||||||
_setup_buildx_step,
|
|
||||||
_setup_uv_step,
|
|
||||||
_trivy_step,
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# ── Override action refs with full GitHub URLs ───────────────────
|
||||||
|
# Gitea Actions resolves short refs (e.g. actions/checkout@v4) against
|
||||||
|
# the local Gitea instance. Use full URLs to pull from GitHub.
|
||||||
|
|
||||||
|
|
||||||
|
def _checkout_step() -> str:
|
||||||
|
return """\
|
||||||
|
- name: Checkout
|
||||||
|
uses: https://github.com/actions/checkout@v4"""
|
||||||
|
|
||||||
|
|
||||||
|
def _setup_buildx_step() -> str:
|
||||||
|
return """\
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
uses: https://github.com/docker/setup-buildx-action@v3"""
|
||||||
|
|
||||||
|
|
||||||
|
def _setup_uv_step(uv_version: str) -> str:
|
||||||
|
return f"""\
|
||||||
|
- name: Set up uv
|
||||||
|
uses: https://github.com/astral-sh/setup-uv@v4
|
||||||
|
with:
|
||||||
|
version: {uv_version}"""
|
||||||
|
|
||||||
|
|
||||||
|
def _build_push_step(
|
||||||
|
img: dict,
|
||||||
|
tags_expr: str,
|
||||||
|
registry: str,
|
||||||
|
owner_repo: str,
|
||||||
|
*,
|
||||||
|
no_cache: bool = False,
|
||||||
|
load_only: bool = False,
|
||||||
|
) -> str:
|
||||||
|
name = img["name"]
|
||||||
|
push = "false" if load_only else "true"
|
||||||
|
lines = f"""\
|
||||||
|
- name: Build {name}
|
||||||
|
uses: https://github.com/docker/build-push-action@v6
|
||||||
|
with:
|
||||||
|
context: {img["context"]}
|
||||||
|
file: {img["dockerfile"]}
|
||||||
|
push: {push}
|
||||||
|
tags: {tags_expr}"""
|
||||||
|
if load_only:
|
||||||
|
lines += "\n load: true"
|
||||||
|
if no_cache:
|
||||||
|
lines += "\n no-cache: true"
|
||||||
|
return lines
|
||||||
|
|
||||||
|
|
||||||
|
def _trivy_step(
|
||||||
|
img: dict,
|
||||||
|
tag: str,
|
||||||
|
registry: str,
|
||||||
|
owner_repo: str,
|
||||||
|
) -> str:
|
||||||
|
name = img["name"]
|
||||||
|
sev = img.get("trivy_severity", "HIGH,CRITICAL")
|
||||||
|
ec = img.get("trivy_exit_code", 0)
|
||||||
|
return f"""\
|
||||||
|
- name: Scan {name}
|
||||||
|
uses: https://github.com/aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
image-ref: {registry}/{owner_repo}/{name}:{tag}
|
||||||
|
severity: {sev}
|
||||||
|
exit-code: "{ec}"
|
||||||
|
format: json
|
||||||
|
output: {name}-scan.json"""
|
||||||
|
|
||||||
|
|
||||||
|
def _upload_artifact_step(name: str, path: str) -> str:
|
||||||
|
return f"""\
|
||||||
|
- name: Upload {name}
|
||||||
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: {name}
|
||||||
|
path: "{path}\""""
|
||||||
|
|
||||||
|
|
||||||
|
def _download_artifact_step(name: str) -> str:
|
||||||
|
return f"""\
|
||||||
|
- name: Download {name}
|
||||||
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: {name}"""
|
||||||
|
|
||||||
|
|
||||||
# ── Gitea-specific helpers ───────────────────────────────────────
|
# ── Gitea-specific helpers ───────────────────────────────────────
|
||||||
|
|
||||||
|
|
||||||
@@ -26,7 +109,7 @@ def _docker_login_step(registry: str) -> str:
|
|||||||
"""Login using PAT secret — GITEA_TOKEN can't push to registry."""
|
"""Login using PAT secret — GITEA_TOKEN can't push to registry."""
|
||||||
return f"""\
|
return f"""\
|
||||||
- name: Log in to container registry
|
- name: Log in to container registry
|
||||||
uses: docker/login-action@v3
|
uses: https://github.com/docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: {registry}
|
registry: {registry}
|
||||||
username: ${{{{ secrets.REGISTRY_USER }}}}
|
username: ${{{{ secrets.REGISTRY_USER }}}}
|
||||||
@@ -135,7 +218,7 @@ jobs:
|
|||||||
{scan_block}
|
{scan_block}
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans
|
name: trivy-scans
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -149,7 +232,7 @@ jobs:
|
|||||||
{_setup_uv_step(uv_version)}
|
{_setup_uv_step(uv_version)}
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans
|
name: trivy-scans
|
||||||
|
|
||||||
@@ -222,7 +305,7 @@ jobs:
|
|||||||
{scan_block}
|
{scan_block}
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-harden
|
name: trivy-scans-harden
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -236,7 +319,7 @@ jobs:
|
|||||||
{_setup_uv_step(uv_version)}
|
{_setup_uv_step(uv_version)}
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-harden
|
name: trivy-scans-harden
|
||||||
|
|
||||||
@@ -316,7 +399,7 @@ jobs:
|
|||||||
{scan_block}
|
{scan_block}
|
||||||
|
|
||||||
- name: Upload scan results
|
- name: Upload scan results
|
||||||
uses: actions/upload-artifact@v4
|
uses: https://github.com/actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-rebuild
|
name: trivy-scans-rebuild
|
||||||
path: "*-scan.json"
|
path: "*-scan.json"
|
||||||
@@ -330,7 +413,7 @@ jobs:
|
|||||||
{_setup_uv_step(uv_version)}
|
{_setup_uv_step(uv_version)}
|
||||||
|
|
||||||
- name: Download scan results
|
- name: Download scan results
|
||||||
uses: actions/download-artifact@v4
|
uses: https://github.com/actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: trivy-scans-rebuild
|
name: trivy-scans-rebuild
|
||||||
|
|
||||||
@@ -368,7 +451,7 @@ def _gen_infra_ci(
|
|||||||
{_checkout_step()}
|
{_checkout_step()}
|
||||||
|
|
||||||
- name: Hadolint {name}
|
- name: Hadolint {name}
|
||||||
uses: hadolint/hadolint-action@v3.1.0
|
uses: https://github.com/hadolint/hadolint-action@v3.1.0
|
||||||
with:
|
with:
|
||||||
dockerfile: {img["dockerfile"]}
|
dockerfile: {img["dockerfile"]}
|
||||||
|
|
||||||
@@ -417,7 +500,7 @@ jobs:
|
|||||||
run: uv build --out-dir dist/
|
run: uv build --out-dir dist/
|
||||||
|
|
||||||
- name: Create release
|
- name: Create release
|
||||||
uses: softprops/action-gh-release@v2
|
uses: https://github.com/softprops/action-gh-release@v2
|
||||||
with:
|
with:
|
||||||
files: |
|
files: |
|
||||||
dist/*.whl
|
dist/*.whl
|
||||||
|
|||||||
Reference in New Issue
Block a user