|
| 1 | +# |
| 2 | +# Copyright (c) 2023, The OpenThread Authors. |
| 3 | +# All rights reserved. |
| 4 | +# |
| 5 | +# Redistribution and use in source and binary forms, with or without |
| 6 | +# modification, are permitted provided that the following conditions are met: |
| 7 | +# 1. Redistributions of source code must retain the above copyright |
| 8 | +# notice, this list of conditions and the following disclaimer. |
| 9 | +# 2. Redistributions in binary form must reproduce the above copyright |
| 10 | +# notice, this list of conditions and the following disclaimer in the |
| 11 | +# documentation and/or other materials provided with the distribution. |
| 12 | +# 3. Neither the name of the copyright holder nor the |
| 13 | +# names of its contributors may be used to endorse or promote products |
| 14 | +# derived from this software without specific prior written permission. |
| 15 | +# |
| 16 | +# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" |
| 17 | +# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| 18 | +# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| 19 | +# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE |
| 20 | +# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR |
| 21 | +# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF |
| 22 | +# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS |
| 23 | +# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN |
| 24 | +# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
| 25 | +# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE |
| 26 | +# POSSIBILITY OF SUCH DAMAGE. |
| 27 | +# |
| 28 | + |
| 29 | +name: Docker |
| 30 | + |
| 31 | +on: |
| 32 | + push: |
| 33 | + branches-ignore: |
| 34 | + - 'dependabot/**' |
| 35 | + pull_request: |
| 36 | + branches: |
| 37 | + - 'main' |
| 38 | + |
| 39 | +concurrency: |
| 40 | + group: ${{ github.workflow }}-${{ github.event.pull_request.number || (github.repository == 'openthread/ot-efr32' && github.run_id) || github.ref }} |
| 41 | + cancel-in-progress: true |
| 42 | + |
| 43 | +permissions: # added using https://github.com/step-security/secure-workflows |
| 44 | + contents: read |
| 45 | + |
| 46 | +jobs: |
| 47 | + buildx: |
| 48 | + name: buildx |
| 49 | + runs-on: ubuntu-22.04 |
| 50 | + steps: |
| 51 | + - name: Harden Runner |
| 52 | + uses: step-security/harden-runner@6b3083af2869dc3314a0257a42f4af696cc79ba3 # v2.3.1 |
| 53 | + with: |
| 54 | + egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs |
| 55 | + |
| 56 | + - uses: actions/checkout@ac593985615ec2ede58e132d2e21d2b1cbd6127c # v3.3.0 |
| 57 | + with: |
| 58 | + submodules: true |
| 59 | + |
| 60 | + - name: Prepare |
| 61 | + id: prepare |
| 62 | + run: | |
| 63 | + DOCKER_IMAGE=siliconlabsinc/ot-efr32-dev |
| 64 | + DOCKER_FILE=Dockerfile |
| 65 | + DOCKER_PLATFORMS=linux/amd64 |
| 66 | + VERSION=latest |
| 67 | +
|
| 68 | + TAGS="--tag ${DOCKER_IMAGE}:${VERSION}" |
| 69 | +
|
| 70 | + echo "docker_image=${DOCKER_IMAGE}" >> $GITHUB_OUTPUT |
| 71 | + echo "version=${VERSION}" >> $GITHUB_OUTPUT |
| 72 | + echo "buildx_args=--platform ${DOCKER_PLATFORMS} \ |
| 73 | + --build-arg OT_GIT_REF=${{ github.sha }} \ |
| 74 | + --build-arg VERSION=${VERSION} \ |
| 75 | + --build-arg BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ') \ |
| 76 | + --build-arg VCS_REF=${GITHUB_SHA::8} \ |
| 77 | + ${TAGS} --file ${DOCKER_FILE} ." >> $GITHUB_OUTPUT |
| 78 | +
|
| 79 | + - name: Set up Docker Buildx |
| 80 | + uses: docker/setup-buildx-action@4b4e9c3e2d4531116a6f8ba8e71fc6e2cb6e6c8c # v2.5.0 |
| 81 | + |
| 82 | + - name: Docker Buildx (build) |
| 83 | + run: | |
| 84 | + docker buildx build --output "type=image,push=false" ${{ steps.prepare.outputs.buildx_args }} |
| 85 | +
|
| 86 | + - name: Login to DockerHub |
| 87 | + if: success() && github.repository == 'SiliconLabs/ot-efr32' && github.event_name != 'pull_request' |
| 88 | + uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a # v2.1.0 |
| 89 | + with: |
| 90 | + username: ${{ secrets.DOCKER_USERNAME }} |
| 91 | + password: ${{ secrets.DOCKER_PASSWORD }} |
| 92 | + |
| 93 | + - name: Docker Buildx (push) |
| 94 | + if: success() && github.repository == 'SiliconLabs/ot-efr32' && github.event_name != 'pull_request' |
| 95 | + run: | |
| 96 | + docker buildx build --output "type=image,push=true" ${{ steps.prepare.outputs.buildx_args }} |
| 97 | +
|
| 98 | + - name: Inspect Image |
| 99 | + if: always() && github.repository == 'SiliconLabs/ot-efr32' && github.event_name != 'pull_request' |
| 100 | + run: | |
| 101 | + docker buildx imagetools inspect ${{ steps.prepare.outputs.docker_image }}:${{ steps.prepare.outputs.version }} |
0 commit comments