2626 steps :
2727
2828 - name : Checkout repository
29- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
30- # https://github.com/actions/checkout/releases/tag/v4.1.1
29+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
3130
32- - name : Setup Go
33- uses : actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
34- # https://github.com/actions/setup-go/releases/tag/v5.0.0
35- with :
36- go-version-file : ' go.mod'
37-
38- - name : Build and package
31+ - name : Build Binary
3932 run : |
4033 ./scripts/build
4134 mkdir -p dist/artifacts
4437 ARCH : " ${{ matrix.arch}}"
4538 GOARCH : " ${{ matrix.arch}}"
4639
47- - name : Generate checksum files
40+ - name : Prepare Artifacts
4841 run : |
49- ls -lR dist
5042 cd dist/artifacts
5143 sha256sum webhook-linux-${{ matrix.arch }} > sha256sum-${{ matrix.arch }}.txt
5244
@@ -67,10 +59,10 @@ jobs:
6759
6860 - name : Checkout repository
6961 # https://github.com/actions/checkout/releases/tag/v4.1.1
70- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
62+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
7163
7264 - name : package-helm
73- run : ./scripts/ package-helm
65+ run : make package-helm
7466
7567 - name : Download the amd64 artifacts
7668 uses : actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
@@ -113,71 +105,61 @@ jobs:
113105 needs : build
114106 steps :
115107 - name : Checkout repository
116- # https://github.com/actions/checkout/releases/tag/v4.1.1
117- uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
118-
108+ uses : actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
119109 - name : Download the artifacts
120110 uses : actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
121- # https://github.com/actions/download-artifact/releases/tag/v4.1.7
122111 with :
123112 name : webhook-artifacts-${{ matrix.arch }}
124113 path : dist/artifacts
125-
126114 - name : Move binary to bin/
127115 run : |
128116 mkdir -p bin/
129117 cp -v dist/artifacts/webhook-linux-${{ matrix.arch }} bin/webhook
130118 chmod +x bin/webhook
131119
132- # PANDARIA
133- # - name: "Read vault secrets"
134- # uses: rancher-eio/read-vault-secrets@main
135- # with:
136- # secrets: |
137- # secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
138- # secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
139-
140120 - name : Set up QEMU
141- # https://github.com/docker/setup-qemu-action/releases/tag/v3.1.0
142- uses : docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
143-
121+ uses : docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
144122 - name : Set up Docker Buildx
145- uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
146- # https://github.com/docker/setup-buildx-action/releases/tag/v3.4.0
147-
123+ uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
148124 - name : Log in to the Container registry
149- # https://github.com/docker/login-action/releases/tag/v3.2.0
150- uses : docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
125+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
151126 with :
152127 registry : ${{ env.REGISTRY }}
153128 username : ${{ secrets.TCR_USERNAME }}
154129 password : ${{ secrets.TCR_TOKEN }}
155130
131+ - name : Set Version/Commit
132+ run : |
133+ source ./scripts/version
134+ echo "VERSION=${VERSION}" >> $GITHUB_ENV
135+ echo "COMMIT=${COMMIT}" >> $GITHUB_ENV
136+
156137 - name : Build and push the webhook image
157- id : build
158- # https://github.com/docker/build-push-action/releases/tag/v6.3.0
159- uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
138+ uses : docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
160139 with :
161140 context : .
162141 file : ./package/Dockerfile
142+ secrets : |
143+ token=${{ secrets.RD_ONLY_GH_TOKEN }}
163144 platforms : " linux/${{ matrix.arch }}"
164145 outputs : type=image,name=${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook,push-by-digest=true,name-canonical=true,push=true
146+ build-args : |
147+ VERSION=${{ env.VERSION }}
148+ COMMIT=${{ env.COMMIT }}
149+ GOPRIVATE=github.com/cnrancher
165150
166151 - name : Export digest
167152 run : |
168153 mkdir -p /tmp/digests
169154 digest="${{ steps.build.outputs.digest }}"
170155 touch "/tmp/digests/${digest#sha256:}"
171-
172156 - name : Upload digest
173157 uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
174- # https://github.com/actions/upload-artifact/releases/tag/v4.3.3
175158 with :
176159 name : digests-${{ matrix.arch }}
177160 path : /tmp/digests/*
178161 if-no-files-found : error
179162 retention-days : 1
180-
181163 merge :
182164 permissions :
183165 id-token : write
@@ -186,33 +168,19 @@ jobs:
186168 steps :
187169 - name : Download digests
188170 uses : actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
189- # https://github.com/actions/download-artifact/releases/tag/v4.1.7
190171 with :
191172 path : /tmp/digests
192173 pattern : digests-*
193174 merge-multiple : true
194-
195175 - name : Set up Docker Buildx
196- uses : docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
197- # https://github.com/docker/setup-buildx-action/releases/tag/v3.4.0
198-
199- # PANDARIA
200- # - name: "Read vault secrets"
201- # uses: rancher-eio/read-vault-secrets@main
202- # with:
203- # secrets: |
204- # secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
205- # secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
176+ uses : docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
206177
207178 - name : Log in to the Container registry
208- uses : docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
209- # https://github.com/docker/login-action/releases/tag/v3.2.0
179+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
210180 with :
211181 registry : ${{ env.REGISTRY }}
212182 username : ${{ secrets.TCR_USERNAME }}
213183 password : ${{ secrets.TCR_TOKEN }}
214-
215- # setup tag name
216184 - if : ${{ startsWith(github.ref, 'refs/tags/') }}
217185 run : |
218186 echo TAG_NAME=$(echo $GITHUB_REF | sed -e "s|refs/tags/||") >> $GITHUB_ENV
@@ -222,6 +190,7 @@ jobs:
222190 run : |
223191 docker buildx imagetools create -t ${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook:${{ env.TAG_NAME }} \
224192 $(printf '${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook@sha256:%s ' *)
193+
225194 image-sign :
226195 permissions :
227196 contents : read
0 commit comments