Files
skiko/.github/workflows/publish-dry-run.yml
Ivan Matkov 1b3f124b9d Build Docker images locally when Dockerfiles change (#1161)
Fixes [SKIKO-1103](https://youtrack.jetbrains.com/issue/SKIKO-1103)
Properly handle Dockerfile changes in CI

### 1. Handle Dockerfile Changes in CI
When a PR modifies both the `Dockerfile` and C++ source, CI must build
the library against the **new** container logic before merging to catch
compatibility issues.
Workflows now detect `Dockerfile` changes and automatically build images
locally before running tests. When no `Dockerfile` changes are detected,
published images from `ghcr.io` are used.

### 2. Avoid GLIBC Mismatches: Run GitHub Actions Outside Containers
Running GitHub Actions native steps (like `actions/checkout`) inside
custom containers causes GLIBC version mismatches since GitHub's
Node.js-based actions require newer GLIBC than Amazon Linux 2 provides.
This change introduced new composite action `docker-skiko-run` that runs
GitHub actions outside the container on `ubuntu-24.04` runner, and only
executes build/test commands inside the Docker container via `docker
run`.

### 3. Environment Alignment: Use `linux-compat` for GitHub Actions
Builds
GitHub Actions used Ubuntu 20.04 images with GLIBC 2.31, while TeamCity
publishing used Amazon Linux 2 with GLIBC 2.26. This mismatch could mask
GLIBC compatibility issues during PR validation.
Most GitHub Actions workflows now use `linux-compat` (Amazon Linux 2).
- Web builds are out of the scope here because emsdk requires newer
GLIBC.
- Cross-compilation is out of the scope because there is no simply way
to get arm shared libraries to x64 image on AL2

Note: TeamCity publishing should be updated to use `linux-compat` too

### 4. Introduce Orchestrator Workflows
New orchestrator workflows compose existing test/build/docs workflows:
- **`pull-request.yml`** - Runs on every PR: detects Docker changes,
builds images if needed (dry-run), runs tests + publish dry run + docs
validation
- **`post-merge.yml`** - Runs on push to master/release: detects Docker
changes, publishes images if changed, runs tests + publish dry run +
docs publication

So, we should have fewer "Run CI" temporary PRs now

### 5. Documentation as Pre-Merge Check
Documentation builds now run inside the same `linux-compat` Docker
environment used for library builds, and are validated as part of PR
checks (previously only ran post-merge).


### 6. Docker Tags Use Branch Names
Published Docker images are tagged with the branch name (e.g., `master`,
`release/0.9.46`), so the release branches might publish its own version
of the image. This way changes in `master` shouldn't prevent making a
patch for a previous version if it's required
2026-02-12 14:15:13 +01:00

142 lines
3.7 KiB
YAML

name: Skiko Publish Dry Run
on:
workflow_call: # Allow being called by other workflows
jobs:
Android:
name: 'Android Publish Dry Run'
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/setup-prerequisites
name: 'Setup Prerequisites'
- uses: ./.github/actions/docker-skiko-run
name: 'Publish Maven Local'
with:
image_name: linux-compat
command: |
./gradlew --no-daemon --stacktrace \
-Pskiko.android.enabled=true \
:skiko:publishToMavenLocal
- uses: ./.github/actions/docker-skiko-run
name: 'Check Android Sample'
with:
image_name: linux-compat
working_directory: samples/SkiaAndroidSample
command: |
./gradlew --no-daemon --stacktrace \
packageRelease
Web:
name: 'Web Publish Dry Run'
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/setup-prerequisites
name: 'Setup Prerequisites'
- uses: ./.github/actions/docker-skiko-run
name: 'Publish Maven Local'
with:
image_name: linux-emscripten-amd64
command: |
./gradlew --no-daemon --stacktrace \
-Pskiko.wasm.enabled=true \
:skiko:publishToMavenLocal
Linux:
name: 'Linux Publish Dry Run'
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/setup-prerequisites
name: 'Setup Prerequisites'
- uses: ./.github/actions/docker-skiko-run
name: 'Publish Maven Local'
with:
image_name: linux-compat
command: |
./gradlew --no-daemon --stacktrace \
-Pskiko.native.enabled=true \
:skiko:publishToMavenLocal
- uses: ./.github/actions/docker-skiko-run
name: 'Check AWT Sample'
with:
image_name: linux-compat
command: |
./gradlew --no-daemon --stacktrace \
:SkiaAwtSample:installDist
macOS:
name: 'macOS Publish Dry Run'
runs-on: macos-15
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: actions/setup-java@v4
name: 'Setup JDK 21'
with:
java-version: '21'
distribution: 'corretto'
- uses: ./.github/actions/setup-prerequisites
name: 'Setup Prerequisites'
- shell: bash
name: 'Publish Maven Local'
run: |
./gradlew --no-daemon --stacktrace \
-Pskiko.native.enabled=true \
:skiko:publishToMavenLocal
- shell: bash
name: 'Check AWT Sample'
run: |
./gradlew --no-daemon --stacktrace \
:SkiaAwtSample:installDist
Windows:
name: 'Windows Publish Dry Run'
runs-on: windows-2022
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: microsoft/setup-msbuild@v1
- uses: ilammy/msvc-dev-cmd@v1
- uses: actions/setup-java@v4
name: 'Setup JDK 21'
with:
java-version: '21'
distribution: 'corretto'
- uses: ./.github/actions/setup-prerequisites
name: 'Setup Prerequisites'
- shell: bash
name: 'Publish Maven Local'
run: |
./gradlew --no-daemon --stacktrace \
-Pskiko.native.enabled=true \
:skiko:publishToMavenLocal
- shell: bash
name: 'Check AWT Sample'
run: |
./gradlew --no-daemon --stacktrace \
:SkiaAwtSample:installDist