Merge pull request #212 from eclipse-tractusx/release/v4.0.0-alpha.2 #20
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
############################################################### | |
# Copyright (c) 2024 Contributors to the Eclipse Foundation | |
# | |
# See the NOTICE file(s) distributed with this work for additional | |
# information regarding copyright ownership. | |
# | |
# This program and the accompanying materials are made available under the | |
# terms of the Apache License, Version 2.0 which is available at | |
# https://www.apache.org/licenses/LICENSE-2.0. | |
# | |
# Unless required by applicable law or agreed to in writing, software | |
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT | |
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the | |
# License for the specific language governing permissions and limitations | |
# under the License. | |
# | |
# SPDX-License-Identifier: Apache-2.0 | |
############################################################### | |
name: Release | |
on: | |
workflow_dispatch: | |
push: | |
paths: | |
- 'charts/**' | |
branches: | |
- main | |
jobs: | |
release-helm-chart: | |
# depending on default permission settings for your org (contents being read-only or read-write for workloads), you will have to add permissions | |
# see: https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token | |
permissions: | |
contents: write | |
runs-on: ubuntu-latest | |
outputs: | |
chart-version: ${{ steps.chart-version.outputs.current }} | |
version-check: ${{ steps.version-check.outputs.exists }} | |
steps: | |
- name: Checkout | |
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 | |
with: | |
fetch-depth: 0 | |
- name: Configure Git | |
run: | | |
git config user.name "$GITHUB_ACTOR" | |
git config user.email "[email protected]" | |
- name: Install Helm | |
uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v4 | |
- name: Update Helm dependencies for centralidp | |
run: | | |
cd charts/centralidp | |
helm repo add bitnami-full-index https://raw.githubusercontent.com/bitnami/charts/archive-full-index/bitnami | |
helm dependency update | |
- name: Update Helm dependencies for sharedidp | |
run: | | |
cd charts/sharedidp | |
helm repo add bitnami-full-index https://raw.githubusercontent.com/bitnami/charts/archive-full-index/bitnami | |
helm dependency update | |
- name: Run chart-releaser | |
uses: helm/[email protected] | |
env: | |
CR_TOKEN: "${{ secrets.GITHUB_TOKEN }}" | |
CR_SKIP_EXISTING: "true" | |
# As centralidp and sharedidp are currently always upgraded together, just checking centralidp version | |
- name: Get current chart version from centralidp | |
id: chart-version | |
run: | | |
current=$(cat ./charts/centralidp/Chart.yaml | grep "version:" | head -1 | cut -d ":" -d " " -f2) | |
echo "current=$current" >> $GITHUB_OUTPUT | |
echo "Exported $current chart version" | |
- name: Check for previous version | |
id: version-check | |
run: | | |
exists=$(git tag -l "v${{ steps.chart-version.outputs.current }}") | |
if [[ -n "$exists" ]]; then | |
echo "exists=true" >> $GITHUB_OUTPUT | |
else | |
echo "exists=false" >> $GITHUB_OUTPUT | |
fi | |
release-images: | |
needs: release-helm-chart | |
if: needs.release-helm-chart.outputs.version-check == 'false' | |
permissions: | |
contents: read | |
runs-on: ubuntu-latest | |
strategy: | |
matrix: | |
include: | |
- image: tractusx/portal-iam | |
dockerfile: ./docker/Dockerfile.import | |
dockernotice: ./docker/notice-iam.md | |
outputs: | |
chart-version: ${{ steps.chart-version.outputs.current }} | |
version-check: ${{ steps.version-check.outputs.exists }} | |
steps: | |
- name: Checkout | |
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 | |
with: | |
fetch-depth: 0 | |
- name: Login to DockerHub | |
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0 | |
with: | |
username: ${{ secrets.DOCKER_HUB_USER }} | |
password: ${{ secrets.DOCKER_HUB_TOKEN }} | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1 | |
- name: Set up QEMU | |
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0 | |
# Create SemVer or ref tags dependent of trigger event | |
- name: Docker meta | |
id: meta | |
uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5.5.1 | |
with: | |
images: ${{ matrix.image }} | |
# Automatically prepare image tags; See action docs for more examples. | |
# semver patter will generate tags like these for example :1 :1.2 :1.2.3 | |
tags: | | |
type=ref,event=branch | |
type=ref,event=pr | |
type=raw,value=latest | |
type=raw,value=v${{ needs.release-helm-chart.outputs.chart-version }} | |
type=semver,pattern={{version}},value=${{ needs.release-helm-chart.outputs.chart-version }} | |
type=semver,pattern={{major}},value=${{ needs.release-helm-chart.outputs.chart-version }} | |
type=semver,pattern={{major}}.{{minor}},value=${{ needs.release-helm-chart.outputs.chart-version }} | |
- name: Build and push Docker images | |
uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0 | |
with: | |
context: . | |
file: ${{ matrix.dockerfile }} | |
platforms: linux/amd64, linux/arm64 | |
pull: true | |
push: ${{ github.event_name != 'pull_request' }} | |
tags: ${{ steps.meta.outputs.tags }} | |
labels: ${{ steps.meta.outputs.labels }} | |
# https://github.com/peter-evans/dockerhub-description | |
- name: Update Docker Hub description | |
uses: peter-evans/dockerhub-description@e98e4d1628a5f3be2be7c231e50981aee98723ae # v4.0.0 | |
with: | |
username: ${{ secrets.DOCKER_HUB_USER }} | |
password: ${{ secrets.DOCKER_HUB_TOKEN }} | |
repository: ${{ matrix.image }} | |
readme-filepath: ${{ matrix.dockernotice }} | |
create-tag: | |
needs: [release-helm-chart, release-images] | |
if: needs.release-helm-chart.outputs.version-check == 'false' | |
permissions: | |
contents: write | |
runs-on: ubuntu-latest | |
steps: | |
- name: Checkout | |
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1 | |
with: | |
fetch-depth: 0 | |
- name: Create and push git tag | |
run: | | |
git tag v${{ needs.release-helm-chart.outputs.chart-version }} | |
git push origin v${{ needs.release-helm-chart.outputs.chart-version }} |