Secret Scan / scan (push) Successful in 4s
Build App (Preview) / compute-version (pull_request) Successful in 3s
Secret Scan / scan (pull_request) Successful in 4s
Build App (Preview) / create-release (pull_request) Successful in 1s
Build App (Preview) / build-macos (pull_request) Successful in 2m41s
Build App (Preview) / build-windows (pull_request) Successful in 4m52s
Build App (Preview) / build-linux (pull_request) Successful in 8m0s
Build App (Preview) / prune-previews (pull_request) Successful in 2s
Build Container / build-container (pull_request) Successful in 10m21s
Every layer of both architectures built. The job then died exporting to act_runner's emulated GitHub Actions cache service, which it could not route to: `GetCacheEntryDownloadURL ... dial tcp 192.168.1.126:40649: no route to host`. On a pull_request `push:` is false, so this job pushes nothing and the cache is its only output — which means a network problem between the buildx `docker-container` builder and the runner host threw away a complete, successful validation of the Dockerfile on linux/amd64 and linux/arm64. A cache is an optimisation; it must degrade to "slow", never to "red". Only the exporter needs the flag. The import is already non-fatal — the build ran all 37 layers after warning it could not read the cache. This does not fix the routing itself, so builds stay uncached until that is sorted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0145mQi9NZiCDrznBUEEDE4n
76 lines
2.6 KiB
YAML
76 lines
2.6 KiB
YAML
name: Build Container
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- "container/**"
|
|
- ".gitea/workflows/build.yml"
|
|
pull_request:
|
|
branches: [main]
|
|
paths:
|
|
- "container/**"
|
|
- ".gitea/workflows/build.yml"
|
|
|
|
env:
|
|
REGISTRY: repo.anhonesthost.net
|
|
IMAGE_NAME: cybercovellc/triple-c/triple-c-sandbox
|
|
|
|
jobs:
|
|
build-container:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@v3
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Login to Gitea Container Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ gitea.actor }}
|
|
password: ${{ secrets.REGISTRY_TOKEN }}
|
|
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
username: shadowdao
|
|
password: ${{ secrets.GH_PAT }}
|
|
|
|
- name: Build and push container image
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: ./container
|
|
file: ./container/Dockerfile
|
|
platforms: linux/amd64,linux/arm64
|
|
push: ${{ gitea.event_name == 'push' }}
|
|
tags: |
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest
|
|
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ gitea.sha }}
|
|
ghcr.io/shadowdao/triple-c-sandbox:latest
|
|
ghcr.io/shadowdao/triple-c-sandbox:${{ gitea.sha }}
|
|
# `ignore-error` is what stops a cache failure failing a build that
|
|
# already succeeded. act_runner emulates the GitHub Actions cache
|
|
# service on the runner host's LAN address, and the `docker-container`
|
|
# builder `setup-buildx-action` creates could not route to it —
|
|
# every layer of both arches built, then the job died on
|
|
# `GetCacheEntryDownloadURL: no route to host` while exporting.
|
|
#
|
|
# On a pull_request `push:` above is false, so this job pushes
|
|
# nothing and the cache is its only output: failing it discarded a
|
|
# complete, successful validation of the Dockerfile for both
|
|
# architectures. A cache is an optimisation and must degrade to
|
|
# "slow", never to "red".
|
|
#
|
|
# The import is already non-fatal — the build ran all 37 layers after
|
|
# warning that it could not read the cache — so only the exporter
|
|
# needs the flag.
|
|
cache-from: type=gha
|
|
cache-to: type=gha,mode=max,ignore-error=true
|