mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 07:58:25 +08:00
* ci: build release binaries with Nix Refs #1683 Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: build VM artifacts with Nix Refs #1683 Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: build images from Nix artifacts Refs #1683 Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(nix): prevent host header leakage Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: parallelize artifact builds Refs #1683 Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: build external driver test artifacts Refs #1683 Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(nix): disable mold in musl shells Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: key Rust cache by Nix shell derivation Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: refactor end-to-end workflows Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: split platform binary workflows Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: remove obsolete native build workflows Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: replace disallowed mise action Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: fix refactored e2e lanes Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: check out local result action Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: cache mise installations Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: run docker builds on host runners Signed-off-by: Simon Scatton <sscatton@nvidia.com> * ci: disable unstable kubernetes e2e lanes Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(ci): scope binary builds to cargo packages Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(ci): address zizmor template injection findings Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(ci): resolve remaining zizmor annotations Signed-off-by: Simon Scatton <sscatton@nvidia.com> --------- Signed-off-by: Simon Scatton <sscatton@nvidia.com>
95 lines
2.7 KiB
YAML
95 lines
2.7 KiB
YAML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
name: Docker Build
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
component:
|
|
required: true
|
|
type: string
|
|
binary:
|
|
required: true
|
|
type: string
|
|
target-suffix:
|
|
required: true
|
|
type: string
|
|
image-tag:
|
|
required: false
|
|
type: string
|
|
default: ""
|
|
checkout-ref:
|
|
required: false
|
|
type: string
|
|
default: ""
|
|
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
|
|
jobs:
|
|
build:
|
|
name: ${{ inputs.component }} (${{ matrix.platform }})
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- arch: amd64
|
|
rust_arch: x86_64
|
|
platform: linux/amd64
|
|
runner: linux-amd64-cpu8
|
|
- arch: arm64
|
|
rust_arch: aarch64
|
|
platform: linux/arm64
|
|
runner: linux-arm64-cpu8
|
|
runs-on: ${{ matrix.runner }}
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: ${{ inputs['checkout-ref'] || github.sha }}
|
|
|
|
- uses: ./.github/actions/build-docker-image
|
|
with:
|
|
component: ${{ inputs.component }}
|
|
binary: ${{ inputs.binary }}
|
|
triple: ${{ matrix.rust_arch }}-${{ inputs['target-suffix'] }}
|
|
arch: ${{ matrix.arch }}
|
|
platform: ${{ matrix.platform }}
|
|
image-tag: ${{ inputs.image-tag || github.sha }}
|
|
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
manifest:
|
|
name: ${{ inputs.component }} manifest
|
|
needs: build
|
|
runs-on: linux-amd64-cpu8
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: ${{ inputs['checkout-ref'] || github.sha }}
|
|
|
|
- name: Log in to GHCR
|
|
shell: bash
|
|
run: echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u "${GITHUB_ACTOR}" --password-stdin
|
|
|
|
- name: Create manifest
|
|
shell: bash
|
|
env:
|
|
IMAGE_TAG: ${{ inputs.image-tag || github.sha }}
|
|
INPUTS_COMPONENT: ${{ inputs.component }}
|
|
run: |
|
|
image=ghcr.io/nvidia/openshell/${INPUTS_COMPONENT}
|
|
docker buildx imagetools create \
|
|
--prefer-index=false \
|
|
--tag "$image:${IMAGE_TAG}" \
|
|
"$image:${IMAGE_TAG}-amd64" \
|
|
"$image:${IMAGE_TAG}-arm64"
|
|
|
|
- name: Verify merged manifest SBOM attestation
|
|
shell: bash
|
|
env:
|
|
IMAGE_REF: ghcr.io/nvidia/openshell/${{ inputs.component }}:${{ inputs.image-tag || github.sha }}
|
|
run: tasks/scripts/verify-image-sbom.sh "${IMAGE_REF}" --require-cargo
|