Files
skiko/.github/workflows/docker-publish.yml
Ivan Matkov 1b3f124b9d Build Docker images locally when Dockerfiles change (#1161)
Fixes [SKIKO-1103](https://youtrack.jetbrains.com/issue/SKIKO-1103)
Properly handle Dockerfile changes in CI

### 1. Handle Dockerfile Changes in CI
When a PR modifies both the `Dockerfile` and C++ source, CI must build
the library against the **new** container logic before merging to catch
compatibility issues.
Workflows now detect `Dockerfile` changes and automatically build images
locally before running tests. When no `Dockerfile` changes are detected,
published images from `ghcr.io` are used.

### 2. Avoid GLIBC Mismatches: Run GitHub Actions Outside Containers
Running GitHub Actions native steps (like `actions/checkout`) inside
custom containers causes GLIBC version mismatches since GitHub's
Node.js-based actions require newer GLIBC than Amazon Linux 2 provides.
This change introduced new composite action `docker-skiko-run` that runs
GitHub actions outside the container on `ubuntu-24.04` runner, and only
executes build/test commands inside the Docker container via `docker
run`.

### 3. Environment Alignment: Use `linux-compat` for GitHub Actions
Builds
GitHub Actions used Ubuntu 20.04 images with GLIBC 2.31, while TeamCity
publishing used Amazon Linux 2 with GLIBC 2.26. This mismatch could mask
GLIBC compatibility issues during PR validation.
Most GitHub Actions workflows now use `linux-compat` (Amazon Linux 2).
- Web builds are out of the scope here because emsdk requires newer
GLIBC.
- Cross-compilation is out of the scope because there is no simply way
to get arm shared libraries to x64 image on AL2

Note: TeamCity publishing should be updated to use `linux-compat` too

### 4. Introduce Orchestrator Workflows
New orchestrator workflows compose existing test/build/docs workflows:
- **`pull-request.yml`** - Runs on every PR: detects Docker changes,
builds images if needed (dry-run), runs tests + publish dry run + docs
validation
- **`post-merge.yml`** - Runs on push to master/release: detects Docker
changes, publishes images if changed, runs tests + publish dry run +
docs publication

So, we should have fewer "Run CI" temporary PRs now

### 5. Documentation as Pre-Merge Check
Documentation builds now run inside the same `linux-compat` Docker
environment used for library builds, and are validated as part of PR
checks (previously only ran post-merge).


### 6. Docker Tags Use Branch Names
Published Docker images are tagged with the branch name (e.g., `master`,
`release/0.9.46`), so the release branches might publish its own version
of the image. This way changes in `master` shouldn't prevent making a
patch for a previous version if it's required
2026-02-12 14:15:13 +01:00

160 lines
4.8 KiB
YAML

name: Docker Build and Publish
on:
workflow_dispatch: # Allow manual triggering with an option to publish
inputs:
publish:
description: 'Publish to registry (if false, only dry-run build)'
required: false
type: boolean
default: true
workflow_call: # Allow being called by other workflows
inputs:
publish:
description: 'Publish to registry (if false, only dry-run build)'
required: true
type: boolean
jobs:
changes:
name: 'Detect Docker Changes'
runs-on: ubuntu-24.04
outputs:
linux_amd64: ${{ steps.filter.outputs.linux_amd64 }}
linux_compat: ${{ steps.filter.outputs.linux_compat }}
linux_emscripten_amd64: ${{ steps.filter.outputs.linux_emscripten_amd64 }}
windows: ${{ steps.filter.outputs.windows }}
docker_workflow: ${{ steps.filter.outputs.docker_workflow }}
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: dorny/paths-filter@v3
id: filter
with:
base: ${{ github.event.pull_request.base.sha || github.event.before || 'master' }}
filters: |
docker_workflow:
- '.github/actions/docker-skiko-publish/**'
- '.github/workflows/docker-publish.yml'
linux_amd64:
- 'skiko/docker/linux-amd64/**'
linux_compat:
- 'skiko/docker/linux-compat/**'
linux_emscripten_amd64:
- 'skiko/docker/linux-emscripten-amd64/**'
windows:
- 'skiko/docker/windows/**'
linux-amd64:
name: 'Docker Linux (x64)'
runs-on: ubuntu-24.04
needs: changes
if: |
needs.changes.outputs.linux_amd64 == 'true' ||
needs.changes.outputs.docker_workflow == 'true'
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/docker-skiko-publish
name: 'Build and Publish Docker Image'
id: docker-publish
with:
image_name: linux-amd64
tag: ${{ github.ref_name }}
should_publish: ${{ inputs.publish }}
github_token: ${{ secrets.GITHUB_TOKEN }}
linux-compat:
name: 'Docker Linux (Compatibility)'
runs-on: ubuntu-24.04
needs: changes
if: |
needs.changes.outputs.linux_compat == 'true' ||
needs.changes.outputs.docker_workflow == 'true'
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/docker-skiko-publish
name: 'Build and Publish Docker Image'
id: docker-publish
with:
image_name: linux-compat
platforms: linux/amd64,linux/arm64
tag: ${{ github.ref_name }}
should_publish: ${{ inputs.publish }}
github_token: ${{ secrets.GITHUB_TOKEN }}
linux-emscripten-amd64:
name: 'Docker Linux with Emscripten (x64)'
runs-on: ubuntu-24.04
needs: changes
if: |
needs.changes.outputs.linux_emscripten_amd64 == 'true' ||
needs.changes.outputs.docker_workflow == 'true'
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- uses: ./.github/actions/docker-skiko-publish
name: 'Build and Publish Docker Image'
id: docker-publish
with:
image_name: linux-emscripten-amd64
tag: ${{ github.ref_name }}
should_publish: ${{ inputs.publish }}
github_token: ${{ secrets.GITHUB_TOKEN }}
windows:
name: 'Docker Windows'
runs-on: windows-2022
needs: changes
if: |
needs.changes.outputs.windows == 'true' ||
needs.changes.outputs.docker_workflow == 'true'
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
name: 'Check out code'
- name: 'Set Variables'
shell: pwsh
run: |
"IMAGE_REPOSITORY=$($env:GITHUB_REPOSITORY.ToLower())" >> $env:GITHUB_ENV
$tag = "${{ github.ref_name }}".Replace('/', '-')
"TAG=$tag" >> $env:GITHUB_ENV
- name: 'Log in to GitHub Container Registry'
if: inputs.publish == true
shell: pwsh
run: |
echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u ${{ github.actor }} --password-stdin
- name: 'Build Image'
shell: pwsh
working-directory: ./skiko/docker/windows
run: |
docker build -t "ghcr.io/$($env:IMAGE_REPOSITORY)/windows-amd64:$($env:TAG)" -m 2G .
- name: 'Push Image'
if: inputs.publish == true
shell: pwsh
run: |
docker push "ghcr.io/$($env:IMAGE_REPOSITORY)/windows-amd64:$($env:TAG)"