From deb42fe00178e6d92c71b685ba62a010ea1b92bc Mon Sep 17 00:00:00 2001 From: levinkerschberger <126667618+levinkerschberger@users.noreply.github.com> Date: Tue, 17 Sep 2024 10:15:41 +0200 Subject: [PATCH] CI: Docker Multi-Platform Image (#4) * feat: push docker image on push to main * Extend description in cr-main.yml --------- Co-authored-by: Benjamin Clauss --- ...ld-and-test-backend.yml => ci-feature.yml} | 5 +- .github/workflows/cr-main.yml | 154 ++++++++++++++++++ backend/Dockerfile-CR | 11 ++ 3 files changed, 168 insertions(+), 2 deletions(-) rename .github/workflows/{build-and-test-backend.yml => ci-feature.yml} (89%) create mode 100644 .github/workflows/cr-main.yml create mode 100644 backend/Dockerfile-CR diff --git a/.github/workflows/build-and-test-backend.yml b/.github/workflows/ci-feature.yml similarity index 89% rename from .github/workflows/build-and-test-backend.yml rename to .github/workflows/ci-feature.yml index bfef4098..dd0bf4f4 100644 --- a/.github/workflows/build-and-test-backend.yml +++ b/.github/workflows/ci-feature.yml @@ -1,11 +1,12 @@ -name: Gradle Build +name: Feature Branch Continuous Integration on: push: + branches: + - feature/** jobs: build: - runs-on: ubuntu-latest permissions: contents: read diff --git a/.github/workflows/cr-main.yml b/.github/workflows/cr-main.yml new file mode 100644 index 00000000..f7c8d284 --- /dev/null +++ b/.github/workflows/cr-main.yml @@ -0,0 +1,154 @@ +# This workflow is triggered on pushes to the main branch. +# It builds the agent and creates a multi-arch image for it. +# The image is then pushed to Docker Hub. +# +# The workflow consists of three jobs: +# 1. build-agent: Builds the agent and uploads the resulting JAR as an artifact. +# 2. build-image: Builds a Docker image for multiple platforms with the matrix strategy. +# 3. merge: Merges the images for the different platforms into a manifest list and pushes it to Docker Hub. + +# To make the build faster, we use a matrix strategy to build the image for multiple platforms in parallel. +# The build of the first job is copied over to the image build jobs, so that the application build is only done once. +# QUEMU is used to emulate the different platforms on the GitHub runner. + +# For more information about how to build multi-arch images and advanced settings with Docker Buildx in GitHub actions, see: +# https://docs.docker.com/build/ci/github-actions/multi-platform/ + +name: Main Branch Continuous Release + +on: + push: + branches: + - main + +env: + REGISTRY_IMAGE: inspectit/inspectit-gepard-configserver + +jobs: + build-configserver: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Set up JDK 21 + uses: actions/setup-java@v4 + with: + java-version: '21' + distribution: 'temurin' + + - name: Setup Gradle + uses: gradle/actions/setup-gradle@417ae3ccd767c252f5661f1ace9f835f9654f2b5 # v3.1.0 + with: + build-scan-publish: true + build-scan-terms-of-service-url: "https://gradle.com/terms-of-service" + build-scan-terms-of-service-agree: "yes" + + - name: Build with Gradle + run: ./gradlew build + + - name: Upload artifact + uses: actions/upload-artifact@v3 + with: + name: configserver-artifact + path: backend/build/libs/backend-0.0.1-SNAPSHOT.jar + build-image: + runs-on: ubuntu-latest + needs: build-configserver + strategy: + fail-fast: false + matrix: + platform: + - linux/amd64 + - linux/arm64 + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Prepare + run: | + platform=${{ matrix.platform }} + echo "PLATFORM_PAIR=${platform//\//-}" >> $GITHUB_ENV + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY_IMAGE }} + + - name: Download artifact + uses: actions/download-artifact@v3 + with: + name: configserver-artifact + path: ./ # Download artifact to the root of the Docker build context + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Login to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ vars.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - name: Build and push by digest + id: build + uses: docker/build-push-action@v6 + with: + context: . + file: "./backend/Dockerfile-CR" + platforms: ${{ matrix.platform }} + labels: ${{ steps.meta.outputs.labels }} + outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true + + - name: Export digest + run: | + mkdir -p /tmp/digests + digest="${{ steps.build.outputs.digest }}" + touch "/tmp/digests/${digest#sha256:}" + + - name: Upload digest + uses: actions/upload-artifact@v4 + with: + name: digests-${{ env.PLATFORM_PAIR }} + path: /tmp/digests/* + if-no-files-found: error + retention-days: 1 + + merge: + runs-on: ubuntu-latest + needs: + - build-image + steps: + - name: Download digests + uses: actions/download-artifact@v4 + with: + path: /tmp/digests + pattern: digests-* + merge-multiple: true + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Docker meta + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY_IMAGE }} + + - name: Login to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ vars.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - name: Create manifest list and push + working-directory: /tmp/digests + run: | + docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ + $(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *) + + - name: Inspect image + run: | + docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.meta.outputs.version }} \ No newline at end of file diff --git a/backend/Dockerfile-CR b/backend/Dockerfile-CR new file mode 100644 index 00000000..682c7f83 --- /dev/null +++ b/backend/Dockerfile-CR @@ -0,0 +1,11 @@ +# ---- Runtime Stage ---- +# We use Temurin as it is the default at VHV +FROM eclipse-temurin:21-jre-jammy + +COPY ./backend-0.0.1-SNAPSHOT.jar ./app.jar + +# Expose the port on which the app will run +EXPOSE 8080 + +# Run the application +ENTRYPOINT ["java", "-jar", "/app.jar"] \ No newline at end of file