mirror of
https://github.com/bitsycore/skiko.git
synced 2026-10-05 14:37:26 +00:00
Fixes [SKIKO-1103](https://youtrack.jetbrains.com/issue/SKIKO-1103) Properly handle Dockerfile changes in CI ### 1. Handle Dockerfile Changes in CI When a PR modifies both the `Dockerfile` and C++ source, CI must build the library against the **new** container logic before merging to catch compatibility issues. Workflows now detect `Dockerfile` changes and automatically build images locally before running tests. When no `Dockerfile` changes are detected, published images from `ghcr.io` are used. ### 2. Avoid GLIBC Mismatches: Run GitHub Actions Outside Containers Running GitHub Actions native steps (like `actions/checkout`) inside custom containers causes GLIBC version mismatches since GitHub's Node.js-based actions require newer GLIBC than Amazon Linux 2 provides. This change introduced new composite action `docker-skiko-run` that runs GitHub actions outside the container on `ubuntu-24.04` runner, and only executes build/test commands inside the Docker container via `docker run`. ### 3. Environment Alignment: Use `linux-compat` for GitHub Actions Builds GitHub Actions used Ubuntu 20.04 images with GLIBC 2.31, while TeamCity publishing used Amazon Linux 2 with GLIBC 2.26. This mismatch could mask GLIBC compatibility issues during PR validation. Most GitHub Actions workflows now use `linux-compat` (Amazon Linux 2). - Web builds are out of the scope here because emsdk requires newer GLIBC. - Cross-compilation is out of the scope because there is no simply way to get arm shared libraries to x64 image on AL2 Note: TeamCity publishing should be updated to use `linux-compat` too ### 4. Introduce Orchestrator Workflows New orchestrator workflows compose existing test/build/docs workflows: - **`pull-request.yml`** - Runs on every PR: detects Docker changes, builds images if needed (dry-run), runs tests + publish dry run + docs validation - **`post-merge.yml`** - Runs on push to master/release: detects Docker changes, publishes images if changed, runs tests + publish dry run + docs publication So, we should have fewer "Run CI" temporary PRs now ### 5. Documentation as Pre-Merge Check Documentation builds now run inside the same `linux-compat` Docker environment used for library builds, and are validated as part of PR checks (previously only ran post-merge). ### 6. Docker Tags Use Branch Names Published Docker images are tagged with the branch name (e.g., `master`, `release/0.9.46`), so the release branches might publish its own version of the image. This way changes in `master` shouldn't prevent making a patch for a previous version if it's required
69 lines
2.1 KiB
YAML
69 lines
2.1 KiB
YAML
name: 'Docker Skiko Publish'
|
|
description: 'Build and optionally publish a Docker image to ghcr.io for skiko'
|
|
|
|
inputs:
|
|
image_name:
|
|
description: 'Image name (e.g., linux-compat)'
|
|
required: true
|
|
platforms:
|
|
description: 'Target platforms (e.g., linux/amd64 or linux/amd64,linux/arm64). If not specified, uses runner architecture.'
|
|
required: false
|
|
tag:
|
|
description: 'Image tag (e.g., latest)'
|
|
required: true
|
|
load:
|
|
description: 'Whether to load the image into the local Docker daemon'
|
|
required: false
|
|
default: 'false'
|
|
should_publish:
|
|
description: 'Whether to push the image to the registry'
|
|
required: true
|
|
github_token:
|
|
description: 'GitHub token for authentication (required only if should_publish is true)'
|
|
required: false
|
|
|
|
runs:
|
|
using: 'composite'
|
|
steps:
|
|
- name: 'Set Variables'
|
|
id: vars
|
|
shell: bash
|
|
run: |
|
|
echo "image_namespace=${GITHUB_REPOSITORY,,}" >> $GITHUB_OUTPUT
|
|
|
|
# Normalize tag: replace invalid docker tag characters
|
|
TAG="${{ inputs.tag }}"
|
|
TAG="${TAG//\//-}"
|
|
echo "tag=${TAG}" >> $GITHUB_OUTPUT
|
|
|
|
- name: 'Set up Docker Buildx'
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: 'Log into registry'
|
|
if: inputs.should_publish == 'true'
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ inputs.github_token }}
|
|
|
|
- name: 'Extract metadata'
|
|
id: meta
|
|
uses: docker/metadata-action@v5
|
|
with:
|
|
images: ghcr.io/${{ steps.vars.outputs.image_namespace }}/${{ inputs.image_name }}
|
|
tags: |
|
|
type=raw,value=${{ steps.vars.outputs.tag }}
|
|
|
|
- name: 'Build and push'
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: ./skiko/docker/${{ inputs.image_name }}
|
|
platforms: ${{ inputs.platforms }}
|
|
push: ${{ inputs.should_publish == 'true' }}
|
|
load: ${{ inputs.load == 'true' }}
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max
|