Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,9 @@ HEARTBEAT_NOTIFY_USER=default
# # commands directly on the host. Without this
# # set to "true", full_access is downgraded to
# # workspace_write.
# SANDBOX_IMAGE=ironclaw-worker:latest
# IRONCLAW_APP_IMAGE=ghcr.io/jzkk720/ironclaw:latest
# SANDBOX_IMAGE=ghcr.io/jzkk720/ironclaw-worker:latest
# Keep the app and worker image on the same channel/tag or digest.
# SANDBOX_TIMEOUT_SECS=120
# SANDBOX_MEMORY_LIMIT_MB=2048

Expand Down
46 changes: 34 additions & 12 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
name: Docker Image
name: Build and Publish Docker Images

on:
push:
branches:
- main
# Called by release.yml or other workflows
workflow_call:
inputs:
Expand All @@ -9,6 +12,11 @@ on:
required: false
type: boolean
default: false
source_ref:
description: "Git ref to checkout for reusable workflow runs"
required: false
type: string
default: ""
tag:
description: "Image tag override (leave empty for auto-detect)"
required: false
Expand All @@ -22,6 +30,11 @@ on:
required: false
type: boolean
default: false
source_ref:
description: "Git ref to checkout before building"
required: false
type: string
default: ""
tag:
description: "Image tag override (leave empty for auto-detect)"
required: false
Expand All @@ -32,22 +45,24 @@ on:
- cron: '0 * * * *'

env:
IMAGE_NAME: nearaidev/ironclaw
WORKER_IMAGE_NAME: nearaidev/ironclaw-worker
REGISTRY: ghcr.io
IMAGE_OWNER: jzkk720
IMAGE_NAME: ghcr.io/jzkk720/ironclaw
WORKER_IMAGE_NAME: ghcr.io/jzkk720/ironclaw-worker

jobs:
build:
name: Build & Push
runs-on: ubuntu-24.04
permissions:
contents: read
packages: read
packages: write
actions: write
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event_name == 'schedule' && 'main' || '' }}
ref: ${{ github.event_name == 'workflow_call' && inputs.source_ref || github.event_name == 'workflow_dispatch' && inputs.source_ref || github.event_name == 'schedule' && 'main' || '' }}
persist-credentials: false

- name: Resolve source git commit
Expand Down Expand Up @@ -99,6 +114,12 @@ jobs:
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:staging"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
elif [[ "${EVENT_NAME}" == "push" ]]; then
# Push to main: :latest + :sha-xxx
TAGS="${IMAGE_NAME}:latest"
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:latest"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
else
# Manual dispatch: :sha-xxx only
TAGS="${IMAGE_NAME}:${SHA}"
Expand All @@ -114,21 +135,22 @@ jobs:
echo "worker_tags=${WORKER_TAGS}" >> "$GITHUB_OUTPUT"

# Staging builds get pre-bundled WASM extensions
if [[ "${EVENT_NAME}" == "schedule" || "${INPUT_TAG}" == "staging" ]]; then
if [[ "${EVENT_NAME}" == "schedule" || "${EVENT_NAME}" == "push" || "${INPUT_TAG}" == "staging" ]]; then
echo "target=runtime-staging" >> "$GITHUB_OUTPUT"
else
echo "target=runtime" >> "$GITHUB_OUTPUT"
fi

- name: Log in to Docker Hub
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Check if current git commit is already built
id: check
if: steps.tags.outputs.target == 'runtime-staging'
if: github.event_name == 'schedule' || inputs.tag == 'staging'
env:
SOURCE_SHA: ${{ steps.source_sha.outputs.sha }}
run: |
Expand Down Expand Up @@ -188,7 +210,7 @@ jobs:

- name: Create releases-manager app token
id: app-token
if: steps.check.outputs.skip != 'true'
if: github.repository_owner == 'nearai' && steps.check.outputs.skip != 'true'
continue-on-error: true
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
with:
Expand All @@ -198,7 +220,7 @@ jobs:
repositories: ironclaw-dind

- name: Trigger ironclaw-dind Build & Push
if: steps.app-token.outcome == 'success' && steps.check.outputs.skip != 'true'
if: github.repository_owner == 'nearai' && steps.app-token.outcome == 'success' && steps.check.outputs.skip != 'true'
continue-on-error: true
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
Expand Down
12 changes: 7 additions & 5 deletions .github/workflows/rebuild-release-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@ on:
type: string

env:
IMAGE_NAME: nearaidev/ironclaw
REGISTRY: ghcr.io
IMAGE_NAME: ghcr.io/jzkk720/ironclaw

jobs:
build:
Expand All @@ -22,7 +23,7 @@ jobs:
permissions:
actions: write
contents: read
packages: read
packages: write
steps:
- name: Checkout requested source
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
Expand Down Expand Up @@ -73,11 +74,12 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Log in to Docker Hub
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Detect runtime stage
id: target
Expand Down
59 changes: 36 additions & 23 deletions .github/workflows/release-plz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,43 +9,63 @@ jobs:

# Release unpublished packages.
release-plz-release:
if: ${{ github.repository_owner == 'nearai' }}
name: Release-plz release
runs-on: ubuntu-latest
permissions:
contents: write
actions: write
steps:
- &checkout
name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
fetch-depth: 0
persist-credentials: false
- name: Record release tags before run
shell: bash
run: |
git fetch origin --tags
git tag -l 'ironclaw-v*' | sort > "$RUNNER_TEMP/release-tags-before.txt"
- &install-rust
name: Install Rust toolchain
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
# Generating a GitHub token, so that PRs and tags created by
# the release-plz-action can trigger actions workflows.
- name: Generate GitHub token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
id: generate-token
with:
# GitHub App ID secret name
app-id: ${{ secrets.GH_RELEASES_MANAGER_APP_ID }}
# GitHub App private key secret name
private-key: ${{ secrets.GH_RELEASES_MANAGER_APP_PRIVATE_KEY }}
- name: Run release-plz
uses: release-plz/action@1528104d2ca23787631a1c1f022abb64b34c1e11 # v0.5
with:
command: release
env:
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Detect newly created release tags
id: new-tags
shell: bash
run: |
git fetch origin --tags
git tag -l 'ironclaw-v*' | sort > "$RUNNER_TEMP/release-tags-after.txt"
comm -13 "$RUNNER_TEMP/release-tags-before.txt" "$RUNNER_TEMP/release-tags-after.txt" > "$RUNNER_TEMP/release-tags-new.txt"

if [ -s "$RUNNER_TEMP/release-tags-new.txt" ]; then
echo "created=true" >> "$GITHUB_OUTPUT"
echo "tags<<EOF" >> "$GITHUB_OUTPUT"
cat "$RUNNER_TEMP/release-tags-new.txt" >> "$GITHUB_OUTPUT"
echo "EOF" >> "$GITHUB_OUTPUT"
else
echo "created=false" >> "$GITHUB_OUTPUT"
fi
- name: Dispatch release workflow for new tags
if: steps.new-tags.outputs.created == 'true'
shell: bash
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
CREATED_TAGS: ${{ steps.new-tags.outputs.tags }}
run: |
while IFS= read -r tag; do
[ -n "$tag" ] || continue
gh workflow run release.yml --ref main -f release_tag="$tag"
done <<< "$CREATED_TAGS"

# Create a PR with the new versions and changelog, preparing the next release.
release-plz-pr:
if: ${{ github.repository_owner == 'nearai' }}
name: Release-plz PR
runs-on: ubuntu-latest
permissions:
Expand All @@ -58,16 +78,9 @@ jobs:
- *checkout
- *install-rust
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: Generate GitHub token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
id: generate-token
with:
app-id: ${{ secrets.GH_RELEASES_MANAGER_APP_ID }}
private-key: ${{ secrets.GH_RELEASES_MANAGER_APP_PRIVATE_KEY }}
- name: Run release-plz
- name: Run release-plz PR
uses: release-plz/action@1528104d2ca23787631a1c1f022abb64b34c1e11 # v0.5
with:
command: release-pr
env:
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Loading