name: Build and push image on: push: branches: - master jobs: build-and-push: runs-on: docker # Fully self-contained: run dockerd inside the job container itself # rather than relying on a separate dind service container (its # hostname failed to resolve via the embedded DNS resolver). Needs # the container itself to be privileged so dockerd can run at all. container: image: node:20-bookworm options: --privileged steps: - name: Checkout uses: actions/checkout@v4 - name: Install and start Docker run: | apt-get update apt-get install -y --no-install-recommends ca-certificates curl install -m 0755 -d /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc chmod a+r /etc/apt/keyrings/docker.asc echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian $(. /etc/os-release && echo $VERSION_CODENAME) stable" \ > /etc/apt/sources.list.d/docker.list apt-get update apt-get install -y --no-install-recommends docker-ce docker-ce-cli containerd.io # vfs avoids nested overlayfs (the job container's own root is # itself an overlay mount, and overlay-on-overlay fails). dockerd --storage-driver=vfs & for i in $(seq 1 30); do docker info >/dev/null 2>&1 && break sleep 1 done docker info >/dev/null 2>&1 || { echo "dockerd failed to start"; exit 1; } - name: Log in to Forgejo registry run: echo "${{ secrets.GITHUB_TOKEN }}" | docker login git.rosenvold.tech -u "${{ github.actor }}" --password-stdin - name: Build image run: | docker build \ -t git.rosenvold.tech/lucas/rosenvold-core:latest \ -t git.rosenvold.tech/lucas/rosenvold-core:${{ github.sha }} \ -f Containerfile . - name: Push image run: docker push git.rosenvold.tech/lucas/rosenvold-core --all-tags