Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
F
FoD
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package registry
Container registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
David Schmitz
FoD
Commits
f64a3e74
Unverified
Commit
f64a3e74
authored
1 year ago
by
dschmitz2017
Committed by
GitHub
1 year ago
Browse files
Options
Downloads
Patches
Plain Diff
Update docker-publish.yml
parent
f07d7d0c
Branches
Branches containing commit
No related tags found
No related merge requests found
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
.github/workflows/docker-publish.yml
+16
-12
16 additions, 12 deletions
.github/workflows/docker-publish.yml
with
16 additions
and
12 deletions
.github/workflows/docker-publish.yml
+
16
−
12
View file @
f64a3e74
...
...
@@ -43,20 +43,21 @@ jobs:
# https://github.com/sigstore/cosign-installer
-
name
:
Install cosign
if
:
github.event_name != 'pull_request'
uses
:
sigstore/cosign-installer@
f3c664df7af409cb4873aa5068053ba9d61a57b6
#v2.6.0
uses
:
sigstore/cosign-installer@
6e04d228eb30da1757ee4e1dd75a0ec73a653e06
#v3.1.1
with
:
cosign-release
:
'
v
1
.1
3
.1'
cosign-release
:
'
v
2
.1.1'
# Workaround: https://github.com/docker/build-push-action/issues/461
-
name
:
Setup Docker buildx
uses
:
docker/setup-buildx-action@79abd3f86f79a9d68a23c75a09a9a85889262adf
# Set up BuildKit Docker container builder to be able to build
# multi-platform images and export cache
# https://github.com/docker/setup-buildx-action
-
name
:
Set up Docker Buildx
uses
:
docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226
# v3.0.0
# Login against a Docker registry except on PR
# https://github.com/docker/login-action
-
name
:
Log into registry ${{ env.REGISTRY }}
if
:
github.event_name != 'pull_request'
uses
:
docker/login-action@
28218f9b04b4f3f62068d7b6ce6ca5b26e35336c
uses
:
docker/login-action@
343f7c4344506bcbf9b4de18042ae17996df046d
# v3.0.0
with
:
registry
:
${{ env.REGISTRY }}
username
:
${{ github.actor }}
...
...
@@ -66,7 +67,7 @@ jobs:
# https://github.com/docker/metadata-action
-
name
:
Extract Docker metadata
id
:
meta
uses
:
docker/metadata-action@9
8669ae865ea3cffbcbaa878cf57c20bbf1c6c38
uses
:
docker/metadata-action@9
6383f45573cb7f253c731d3b3ab81c87ef81934
# v5.0.0
with
:
images
:
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
...
...
@@ -74,7 +75,7 @@ jobs:
# https://github.com/docker/build-push-action
-
name
:
Build and push Docker image
id
:
build-and-push
uses
:
docker/build-push-action@
ac9327eae2b366085ac7f6a2d02df8aa8ead720a
uses
:
docker/build-push-action@
0565240e2d4ab88bba5387d719585280857ece09
# v5.0.0
with
:
context
:
.
#file: ./inst/testing/fodexabgp-containerlab1/Dockerfile
...
...
@@ -85,7 +86,6 @@ jobs:
cache-from
:
type=gha
cache-to
:
type=gha,mode=max
# Sign the resulting Docker image digest except on PRs.
# This will only write to the public Rekor transparency log when the Docker
# repository is public to avoid leaking data. If you would like to publish
...
...
@@ -94,7 +94,11 @@ jobs:
-
name
:
Sign the published Docker image
if
:
${{ github.event_name != 'pull_request' }}
env
:
COSIGN_EXPERIMENTAL
:
"
true"
# https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable
TAGS
:
${{ steps.meta.outputs.tags }}
DIGEST
:
${{ steps.build-and-push.outputs.digest }}
# This step uses the identity token to provision an ephemeral certificate
# against the sigstore community Fulcio instance.
run
:
echo "${{ steps.meta.outputs.tags }}" | xargs -I {} cosign sign {}@${{ steps.build-and-push.outputs.digest }}
run
:
echo "${TAGS}" | xargs -I {} cosign sign --yes {}@${DIGEST}
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment