Skip to content

Commit 1a23c3d

Browse files
authored
feat(docker-build): upload image tag as an artifact and publish summary (#163)
1 parent ee5cd7f commit 1a23c3d

3 files changed

Lines changed: 46 additions & 2 deletions

File tree

‎.github/workflows/docker-build.yml‎

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,6 +90,7 @@ jobs:
9090
env:
9191
PLATFORM: ${{ inputs.platform }}
9292
OCI_IMAGE: ${{ inputs.image-name }}:${{ inputs.image-tag }}
93+
IMAGE_TAG: ${{ inputs.image-tag }}
9394
REPORT_MODE: ${{ inputs.security-report }}
9495

9596
steps:
@@ -274,6 +275,19 @@ jobs:
274275
if: ${{ inputs.push }}
275276
run: docker push "$OCI_IMAGE"
276277

278+
- name: Record the pushed image tag
279+
run: |
280+
echo "$IMAGE_TAG" > image-tag.txt
281+
282+
# The promote workflow runs from a separate tag push and reads this artifact
283+
# from the CI run, instead of reconstructing the tag from a prefix.
284+
- name: Upload the image tag for the promote workflow
285+
if: ${{ inputs.push }}
286+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
287+
with:
288+
name: docker-image-tag
289+
path: image-tag.txt
290+
277291
- name: Compute checksum of the Docker image
278292
id: checksum
279293
run: |
@@ -283,6 +297,27 @@ jobs:
283297
echo "checksum=0x${DIGEST}" >> "$GITHUB_OUTPUT"
284298
echo "digest=sha256:${DIGEST}" >> "$GITHUB_OUTPUT"
285299
300+
- name: Summarise the build
301+
env:
302+
PUSH: ${{ inputs.push }}
303+
REGISTRY: ${{ inputs.registry }}
304+
DIGEST: ${{ steps.checksum.outputs.digest }}
305+
CHECKSUM: ${{ steps.checksum.outputs.checksum }}
306+
run: |
307+
{
308+
echo "### 🐳 Built \`$OCI_IMAGE\`"
309+
echo ""
310+
echo "<table><tbody>"
311+
echo "<tr><td><b>Platform</b></td><td>$PLATFORM</td></tr>"
312+
echo "<tr><td><b>Registry</b></td><td>$REGISTRY</td></tr>"
313+
echo "<tr><td><b>Digest</b></td><td><code>$DIGEST</code></td></tr>"
314+
echo "<tr><td><b>Checksum</b></td><td><code>$CHECKSUM</code></td></tr>"
315+
if [ "$PUSH" = "true" ]; then
316+
echo "<tr><td><b>Pushed</b></td><td>✅</td></tr>"
317+
fi
318+
echo "</tbody></table>"
319+
} >> "$GITHUB_STEP_SUMMARY"
320+
286321
# --- SLSA provenance attestation -----
287322
# Requires the permissions id-token: write + attestations: write.
288323
- name: Generate & sign SLSA provenance (keyless)
@@ -296,5 +331,5 @@ jobs:
296331
- name: Cleanup files
297332
if: always()
298333
run: |
299-
rm -f trivy.txt trivy-results.sarif
334+
rm -f trivy.txt trivy-results.sarif image-tag.txt
300335
docker image rm -f "$OCI_IMAGE"

‎docker-build/README.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,14 @@ Perfect for teams looking to streamline their containerization workflow with min
5353
| `username` | Username for Docker Registry authentication | When `push: true` |
5454
| `password` | Password or Personal Access Token for Docker registry authentication (with appropriate permissions) | When `push: true` |
5555

56+
## 📤 Outputs
57+
58+
| Name | Description |
59+
| --- | --- |
60+
| `checksum` | Checksum (`0x...`) of the Docker image |
61+
62+
The built image tag, digest and checksum are visible on the workflow run summary.
63+
5664
## 💻 Example Usage
5765

5866
```yaml
@@ -93,6 +101,7 @@ jobs:
93101
- 🔒 Ensure your Docker Registry credentials are stored securely as GitHub Secrets
94102
- 🔄 The workflow will automatically handle the Docker build and push process
95103
- 🏷️ You can specify any valid Docker tag format in the `tag` input
104+
- 📤 When `push: true`, the applied tag is also saved as a `docker-image-tag` artifact, so `docker-promote` can promote the exact image CI built for a commit rather than reconstruct its tag
96105
- 📅 Consider using dynamic tags based on git tags, commit SHAs, or dates
97106
- 🧪 For testing purposes, you can use the `--dry-run` flag in your own implementation
98107
- 📜 When `attest: true`, the attestation is only generated if `push: true`, and the **caller** workflow must grant the following permissions:

‎docker-build/workflow-sha256‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
45cbab194c7027c476e38ea6b843d97121a99785a1406ae8584f10d150f538c3
1+
c1688238c51571ebf2755cee205def80d47878ca649d17f2f216b4d979d534fe

0 commit comments

Comments
 (0)