Repository navigation
88 lines (83 loc) · 3.32 KB
/
Copy pathbugbash-sandbox-image.yml
File metadata and controls
88 lines (83 loc) · 3.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
# The bug-bash sandbox image (#5714): tests/bugbash/sandbox/Dockerfile, built by build.sh.
#
# Pull requests build it with a read-only token and push nothing. Publishing is manual: only a
# workflow_dispatch run on main publishes, from that run's exact commit, with no cache and no
# artifact from any other run. Each publish builds fresh, and the attestation names that build's
# own output. A person then copies the digest from the job summary into image.json in a pull
# request: no workflow writes to the repo. Nothing here deletes an image.
#
# Until a new image is published and its digest PR merges, runners refuse a checkout whose image
# inputs changed (stale inputs key).
name: Bug-bash sandbox image
on:
pull_request:
paths:
- tests/bugbash/sandbox/Dockerfile
- tests/bugbash/sandbox/build.sh
- bun.lock
- Makefile
- .github/workflows/bugbash-sandbox-image.yml
workflow_dispatch: {}
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
# Never cancel a publish half way. Pull request runs may cancel.
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
build:
name: Build (no push)
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- name: Build
run: |
id=$(make -s bugbash-sandbox-image)
size=$(docker image inspect --format '{{.Size}}' "$id")
echo "Image $id: $size bytes (inputs key $(make -s bugbash-sandbox-key))" | tee -a "$GITHUB_STEP_SUMMARY"
publish:
name: Publish
if: github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: read
# Push ghcr.io/coder/xum-bugbash-sandbox. Only this job, only a manual run on main.
packages: write
# Build provenance for audit (the runner trusts the digest in image.json).
id-token: write
attestations: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
ref: ${{ github.sha }}
persist-credentials: false
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
id: push
run: |
make -s bugbash-sandbox-publish > image.json
# The subject of the attestation is this build's own output (image.json).
echo "image=$(jq -er .image image.json)" >> "$GITHUB_OUTPUT"
echo "digest=$(jq -er .digest image.json)" >> "$GITHUB_OUTPUT"
{
echo '### tests/bugbash/sandbox/image.json'
echo
echo '```json'
cat image.json
echo '```'
} >> "$GITHUB_STEP_SUMMARY"
- name: Attest
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ${{ steps.push.outputs.image }}
subject-digest: ${{ steps.push.outputs.digest }}
push-to-registry: true