A re-fired tag hits the release POST with a 409 and curl -sf turns "already exists" into a red job while the image jobs succeed — observed on boilerroom's v0.1.0 re-fires tonight; this workflow fails the same way. Check-then-create makes the step idempotent. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
56 lines
1.7 KiB
YAML
56 lines
1.7 KiB
YAML
name: Build and Push
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v[0-9]*'
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Create Gitea Release
|
|
# Idempotent: a re-fired tag finds its release already present and
|
|
# says so instead of failing on the 409.
|
|
run: |
|
|
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}/releases"
|
|
auth='Authorization: token ${{ secrets.GITHUB_TOKEN }}'
|
|
if curl -sf -H "$auth" "$api/tags/${{ github.ref_name }}" > /dev/null; then
|
|
echo "release for ${{ github.ref_name }} already exists — nothing to do"
|
|
exit 0
|
|
fi
|
|
curl -sf -X POST \
|
|
-H "$auth" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"tag_name": "${{ github.ref_name }}", "name": "Release ${{ github.ref_name }}", "body": "Automated release for ${{ github.ref_name }}"}' \
|
|
"$api"
|
|
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Login to Gitea Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: git.schweitz.net
|
|
username: ${{ secrets.REGISTRY_USER }}
|
|
password: ${{ secrets.REGISTRY_PASSWORD }}
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v6
|
|
with:
|
|
context: .
|
|
push: true
|
|
provenance: false
|
|
sbom: false
|
|
tags: |
|
|
git.schweitz.net/jpmschweitzer/tatlock:latest
|
|
git.schweitz.net/jpmschweitzer/tatlock:${{ github.ref_name }}
|
|
|
|
- name: Trigger Watchtower update
|
|
if: success()
|
|
run: |
|
|
curl -sf -H "Authorization: Bearer ${{ secrets.WATCHTOWER_TOKEN }}" \
|
|
http://watchtower:8080/v1/update
|