name: build on: push: branches: [main] tags: ["v*"] workflow_dispatch: env: IMAGE: registry.traberph.de/public/homepage # Baked in at build time (canonical URLs); override with a repository variable. SITE_URL: ${{ vars.SITE_URL || 'https://traberph.de' }} # Default Harbor instance baked into the image as an env var (overridable at runtime). HARBOR_URL: ${{ vars.HARBOR_URL || 'https://registry.traberph.de' }} jobs: image: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 # Tag scheme for Flux image automation: -, # e.g. 20260926154233-1a2b3c4. Timestamps sort numerically, see README. - name: Compute tags id: tags run: | ts="$(date -u +%Y%m%d%H%M%S)" sha="$(git rev-parse --short=7 HEAD)" tags="${IMAGE}:${ts}-${sha}" if [ "${GITHUB_REF_TYPE}" = "tag" ]; then tags="${tags},${IMAGE}:${GITHUB_REF_NAME}" else tags="${tags},${IMAGE}:latest" fi echo "tags=${tags}" >> "$GITHUB_OUTPUT" echo "created=$(date -u +%Y-%m-%dT%H:%M:%SZ)" >> "$GITHUB_OUTPUT" echo "sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" echo "Tags: ${tags}" - uses: docker/setup-qemu-action@v4 - uses: docker/setup-buildx-action@v4 - uses: docker/login-action@v4 with: registry: registry.traberph.de username: ${{ secrets.REGISTRY_USERNAME }} password: ${{ secrets.REGISTRY_TOKEN }} - uses: docker/build-push-action@v7 with: context: . platforms: linux/amd64,linux/arm64 push: true tags: ${{ steps.tags.outputs.tags }} build-args: | SITE_URL=${{ env.SITE_URL }} HARBOR_URL=${{ env.HARBOR_URL }} labels: | org.opencontainers.image.source=${{ github.server_url }}/${{ github.repository }} org.opencontainers.image.revision=${{ steps.tags.outputs.sha }} org.opencontainers.image.created=${{ steps.tags.outputs.created }}