Repository navigation
105 lines (101 loc) · 3.5 KB
/
Copy pathdocker-image.yml
File metadata and controls
105 lines (101 loc) · 3.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
name: Docker Runtime Validation
on:
pull_request:
branches: [main]
paths:
- '.github/workflows/docker-image.yml'
- '.github/workflows/nightly.yml'
- '.github/workflows/ci.yml'
- 'scripts/docker/**'
- 'tests/fixtures/docker-runtime/**'
- 'tests/tooling/test_docker*.py'
- 'Cargo.toml'
- 'Cargo.lock'
- 'build.rs'
- 'src/**'
- 'wfl-lsp/Cargo.toml'
- '.wflcfg'
- 'LICENSE'
push:
branches: [main]
paths:
- '.github/workflows/docker-image.yml'
- '.github/workflows/nightly.yml'
- '.github/workflows/ci.yml'
- 'scripts/docker/**'
- 'tests/fixtures/docker-runtime/**'
- 'tests/tooling/test_docker*.py'
- 'Cargo.toml'
- 'Cargo.lock'
- 'build.rs'
- 'src/**'
- 'wfl-lsp/Cargo.toml'
- '.wflcfg'
- 'LICENSE'
workflow_dispatch:
permissions:
contents: read
concurrency:
group: docker-runtime-validation-${{ github.ref }}
cancel-in-progress: true
jobs:
validate:
name: Build and test the consumer Docker image
runs-on: blacksmith-8vcpu-ubuntu-2404
timeout-minutes: 60
env:
CARGO_INCREMENTAL: 0
CARGO_PROFILE_RELEASE_DEBUG: false
CC_x86_64_unknown_linux_musl: musl-gcc
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Test publication policy against the local registry fixture
run: python -m unittest discover -s tests/tooling -p 'test_docker*.py' -v
- name: Install musl toolchain
run: |
sudo apt-get update
sudo apt-get install -y musl-tools musl-dev cmake clang
- uses: dtolnay/rust-toolchain@stable
with:
targets: x86_64-unknown-linux-musl
- uses: Swatinem/rust-cache@v2
with:
shared-key: x86_64-unknown-linux-musl
save-if: ${{ github.ref == 'refs/heads/main' }}
- name: Build the WFL runtime
run: cargo build --release --locked --target x86_64-unknown-linux-musl --bin wfl
- name: Stage the image and verify static linking
id: version
run: |
set -euo pipefail
BIN=target/x86_64-unknown-linux-musl/release/wfl
if readelf -l "$BIN" | grep -q 'Requesting program interpreter'; then
echo '::error::The Docker runtime must be statically linked'
exit 1
fi
mkdir -p target/docker-context
cp "$BIN" target/docker-context/wfl
strip target/docker-context/wfl
cp LICENSE .wflcfg target/docker-context/
echo "version=$(python scripts/docker/publish.py version --repo .)" >> "$GITHUB_OUTPUT"
# Use the runner's Docker CLI within the organization's action allowlist.
- name: Build the image on Blacksmith
env:
VERSION: ${{ steps.version.outputs.version }}
REVISION: ${{ github.sha }}
DOCKER_BUILDKIT: '1'
run: |
docker build --platform linux/amd64 \
--file scripts/docker/Dockerfile \
--build-arg "VERSION=$VERSION" --build-arg "REVISION=$REVISION" \
--tag "wfl-runtime-validation:$REVISION" target/docker-context
- name: Prove other projects can run their test scripts
env:
IMAGE: wfl-runtime-validation:${{ github.sha }}
VERSION: ${{ steps.version.outputs.version }}
run: python scripts/docker/smoke_test.py "$IMAGE" --version "$VERSION"