Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/actions/codegen/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# The codegen hook the hub's run-codegen-pull-request-task.yml runs on each of main and develop.
# The hub task owns the .NET setup, the CSharpier format, and the pull request, so this carries only the generator invocation.
name: NxWitness codegen hook
description: Refresh Make/Version.json and Make/Matrix.json from the upstream product releases.

runs:
using: composite
steps:
- name: Run CreateMatrix codegen step
shell: bash
run: |
set -Eeuo pipefail
dotnet run --project ./CreateMatrix/CreateMatrix.csproj -- \
matrix --versionpath=./Make/Version.json --matrixpath=./Make/Matrix.json --updateversion
78 changes: 78 additions & 0 deletions .github/actions/docker-build-base/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
# The docker-build-base hook the hub's build-docker-task.yml runs before the product images when build-base is set.
# It builds the two shared base images every product Dockerfile starts from, nx-base and nx-base-lsio.
# The base carries one branch-agnostic tag, so only a main publish pushes it, and a develop publish reuses main's.
# The publisher's own build-base job runs it for that push, and the smoke build reaches it through the hub without one.
# No branch reaches the hook, so push stands in for it: a push is a main publish, built multi-arch with a main cache.
# Anything else is a smoke build, amd64 only and never pushed.
name: NxWitness docker-build-base hook
description: Build and optionally push the shared nx-base and nx-base-lsio images.

inputs:
push:
description: Push the base images, which only a main publish sets.
required: true
ref:
description: Accepted because the hub passes it, and unused, since the hub job has already checked it out.
required: false
default: ''

runs:
using: composite
steps:
- name: Select platforms step
id: platforms
shell: bash
env:
PUSH: ${{ inputs.push }}
run: |
set -Eeuo pipefail
if [[ "$PUSH" == "true" ]]; then
echo "platforms=linux/amd64,linux/arm64" >> "$GITHUB_OUTPUT"
else
echo "platforms=linux/amd64" >> "$GITHUB_OUTPUT"
fi

# An arm64 build is non-native on the amd64 runner, so its QEMU emulator is installed only when the build includes it.
- name: Setup QEMU step
if: ${{ contains(steps.platforms.outputs.platforms, 'arm64') }}
uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0
with:
platforms: arm64

- name: Setup Buildx step
uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
with:
platforms: ${{ steps.platforms.outputs.platforms }}

# The hook holds no login, since a composite action cannot read secrets, so the job running it with push set logs in first.
# The hub's own docker-build-base job carries no login, which is why only the smoke build reaches this hook through the hub.
# The inline cache on the pushed tag is what the first cache-from entry reads back on the next publish.
- name: Build and push nx-base step
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
push: ${{ inputs.push == 'true' }}
context: Docker
file: Docker/NxBase.Dockerfile
platforms: ${{ steps.platforms.outputs.platforms }}
tags: docker.io/ptr727/nx-base:ubuntu-noble
cache-from: |
type=registry,ref=docker.io/ptr727/nx-base:ubuntu-noble
type=registry,ref=docker.io/ptr727/nx-base:buildcache-main
cache-to: |
${{ inputs.push == 'true' && 'type=registry,ref=docker.io/ptr727/nx-base:buildcache-main,mode=max,ignore-error=true' || '' }}
${{ inputs.push == 'true' && 'type=inline' || '' }}

- name: Build and push nx-base-lsio step
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
push: ${{ inputs.push == 'true' }}
context: Docker
file: Docker/NxBase-LSIO.Dockerfile
platforms: ${{ steps.platforms.outputs.platforms }}
tags: docker.io/ptr727/nx-base-lsio:ubuntu-noble
cache-from: |
type=registry,ref=docker.io/ptr727/nx-base-lsio:ubuntu-noble
type=registry,ref=docker.io/ptr727/nx-base-lsio:buildcache-main
cache-to: |
${{ inputs.push == 'true' && 'type=registry,ref=docker.io/ptr727/nx-base-lsio:buildcache-main,mode=max,ignore-error=true' || '' }}
${{ inputs.push == 'true' && 'type=inline' || '' }}
56 changes: 56 additions & 0 deletions .github/actions/docker-prepare/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# The docker-prepare hook the hub's build-docker-task.yml runs in place of its single-image default.
# It turns the Make/Matrix.json rows for one branch into the hub's {name, tags, build-args, context, dockerfile, cache-repo} matrix shape.
# The hub core adds LABEL_VERSION from semver2 itself, so the entries carry only the product tags and download args codegen wrote.
name: NxWitness docker-prepare hook
description: Emit the build-docker-task.yml matrix from the Make/Matrix.json rows of one branch.

inputs:
# This hook reads image as an optional filter rather than as a Docker Hub repository.
# The smoke build names the one Ubuntu and one LSIO product it builds, and a publish leaves it empty to build every row.
image:
description: Comma-separated Make/Matrix.json image names to keep, one row per name, or empty for every row of the branch.
required: false
default: ''
branch:
description: The Make/Matrix.json Branch value whose rows to build.
required: true
semver2:
description: Accepted because the hub passes it, and unused, since the hub core adds LABEL_VERSION itself.
required: false
default: ''

outputs:
matrix:
description: Compact JSON array of {name, tags, build-args, context, dockerfile, cache-repo} entries.
value: ${{ steps.emit.outputs.matrix }}

runs:
using: composite
steps:
- name: Emit Make/Matrix.json matrix step
id: emit
shell: bash
env:
NAMES: ${{ inputs.image }}
BRANCH: ${{ inputs.branch }}
run: |
set -Eeuo pipefail
# The cache repository is the first tag without its :tag suffix, the image's own Docker Hub repository.
# A name filter keeps one row per name, since the rows of one product differ only in the upstream version they pin.
# shellcheck disable=SC2016 # $b and $n are jq variables, not shell expansions
matrix=$(jq --compact-output --arg b "$BRANCH" --arg n "$NAMES" '
[.Images[] | select(.Branch == $b)]
| if $n == "" then . else map(select(.Name as $name | $n | split(",") | index($name))) | unique_by(.Name) end
| map({
name: .Name,
tags: .Tags,
"build-args": .Args,
context: "Docker",
dockerfile: "Docker/\(.Name).Dockerfile",
"cache-repo": (.Tags[0] | sub(":[^:]*$"; ""))
})' ./Make/Matrix.json)
if [[ "$(jq 'length' <<<"$matrix")" == "0" ]]; then
echo "::error::Make/Matrix.json holds no rows for branch '$BRANCH' and names '$NAMES'."
exit 1
fi
echo "matrix=$matrix" >> "$GITHUB_OUTPUT"
10 changes: 5 additions & 5 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,18 +15,18 @@
# via the next develop -> main release, those channels would ship
# outdated code in the interim.
# - Codegen workflows take the same dual-target shape for the same
# reason - see .github/workflows/run-codegen-pull-request-task.yml.
# reason - see .github/workflows/run-periodic-codegen-pull-request.yml.
#
# The merge-bot's `case` statement in
# .github/workflows/merge-bot-pull-request.yml dispatches the merge
# method per base ref (squash on develop, merge on main) so both bases
# The hub merge-bot task that
# .github/workflows/merge-bot-pull-request.yml calls dispatches the
# merge method per base ref (squash on develop, merge on main) so both bases
# auto-merge cleanly. `develop` remains strictly forward-only: there
# are no main -> develop back-merges; each branch absorbs its own
# Dependabot PRs and codegen PRs independently.
#
# Security update PRs (CVE-driven) are opened by Dependabot against
# the repo default branch (`main`) regardless of any `target-branch`
# config - the `case` statement handles them in the same code path.
# config - the merge-bot handles them in the same code path.
version: 2
updates:

Expand Down
89 changes: 0 additions & 89 deletions .github/workflows/build-base-images-task.yml

This file was deleted.

Loading
Loading