From b7eff3d5a6ed81677ae7fade8087781f8f8cbcce Mon Sep 17 00:00:00 2001 From: Han Qiao Date: Wed, 14 Dec 2022 14:30:30 +0800 Subject: [PATCH] chore: separate release job for arm and x86 runners (#10951) * chore: separate release job for arm and x86 runners * chore: add missing step dependency * chore: update sha tag * chore: fix image name --- .github/workflows/mirror.yml | 7 +- .github/workflows/publish_image.yml | 121 ++++++++++++++++++++++------ 2 files changed, 101 insertions(+), 27 deletions(-) diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index bacadccbf1e..0a4d1b1fd57 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,10 +1,15 @@ name: Mirror Image on: + workflow_call: + inputs: + version: + required: true + type: string workflow_dispatch: inputs: version: - description: "Image tag" + description: 'Image tag' required: true type: string diff --git a/.github/workflows/publish_image.yml b/.github/workflows/publish_image.yml index fb21fd49d43..f57fd2515d3 100644 --- a/.github/workflows/publish_image.yml +++ b/.github/workflows/publish_image.yml @@ -14,29 +14,39 @@ on: type: string jobs: - publish: + settings: runs-on: ubuntu-latest - permissions: - contents: read - packages: write + outputs: + image_version: ${{ steps.meta.outputs.version }} steps: - id: meta uses: docker/metadata-action@v4 with: images: | supabase/studio - public.ecr.aws/supabase/studio - ghcr.io/supabase/studio flavor: | latest=false tags: | type=ref,event=tag - type=sha,prefix={{date 'YYYYMMDD'}},enable=${{ github.ref_type == 'branch' }} - type=raw,value=${{ inputs.version }},enable=${{ github.event_name != 'push' }} + type=sha,prefix={{date 'YYYYMMDD'}}-,enable=${{ github.event_name == 'push' && github.ref_type == 'branch' }} + type=raw,value=${{ inputs.version }},enable=${{ github.event_name == 'workflow_dispatch' }} - - uses: docker/setup-qemu-action@v2 + release_x86: + needs: settings + runs-on: ubuntu-latest + timeout-minutes: 120 + env: + arch: amd64 + outputs: + image_digest: ${{ steps.build.outputs.digest }} + steps: + - id: meta + uses: docker/metadata-action@v4 with: - platforms: amd64,arm64 + images: | + supabase/studio + tags: | + type=raw,value=${{ needs.settings.outputs.image_version }}_${{ env.arch }} - uses: docker/setup-buildx-action@v2 @@ -46,27 +56,86 @@ jobs: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_PASSWORD }} - - name: Login to ECR - uses: docker/login-action@v2 - with: - registry: public.ecr.aws - username: ${{ secrets.PROD_ACCESS_KEY_ID }} - password: ${{ secrets.PROD_SECRET_ACCESS_KEY }} - - - name: Login to GHCR - uses: docker/login-action@v2 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - - uses: docker/build-push-action@v3 + - id: build + uses: docker/build-push-action@v3 with: push: true context: '{{defaultContext}}' file: studio/Dockerfile target: production - platforms: linux/amd64,linux/arm64 + platforms: linux/${{ env.arch }} tags: ${{ steps.meta.outputs.tags }} cache-from: type=gha cache-to: type=gha,mode=max + + release_arm: + needs: settings + runs-on: arm-runner + timeout-minutes: 120 + env: + arch: arm64 + outputs: + image_digest: ${{ steps.build.outputs.digest }} + steps: + - uses: actions/checkout@v3 + + - id: meta + uses: docker/metadata-action@v4 + with: + images: | + supabase/studio + tags: | + type=raw,value=${{ needs.settings.outputs.image_version }}_${{ env.arch }} + + - uses: docker/login-action@v2 + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - uses: docker/setup-buildx-action@v2 + with: + driver: docker + driver-opts: | + image=moby/buildkit:master + network=host + + - id: build + uses: docker/build-push-action@v3 + with: + push: true + context: . + file: studio/Dockerfile + target: production + platforms: linux/${{ env.arch }} + tags: ${{ steps.meta.outputs.tags }} + no-cache: true + + merge_manifest: + needs: + - settings + - release_x86 + - release_arm + runs-on: ubuntu-latest + steps: + - uses: docker/setup-buildx-action@v2 + + - uses: docker/login-action@v2 + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Merge multi-arch manifests + run: | + docker buildx imagetools create -t supabase/studio:${{ needs.settings.outputs.image_version }} \ + supabase/studio@${{ needs.release_x86.outputs.image_digest }} \ + supabase/studio@${{ needs.release_arm.outputs.image_digest }} + + publish: + needs: + - settings + - merge_manifest + # Call workflow explicitly because events from actions cannot trigger more actions + uses: ./.github/workflows/mirror.yml + with: + version: ${{ needs.settings.outputs.image_version }} + secrets: inherit