Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 38 additions & 3 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,9 +17,13 @@ on:
required: false
type: string
default: ""
# Daily staging build from the staging branch
schedule:
- cron: '0 6 * * *'

env:
IMAGE_NAME: nearaidev/ironclaw
WORKER_IMAGE_NAME: nearaidev/ironclaw-worker

jobs:
build:
Expand All @@ -32,6 +36,8 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'schedule' && 'staging' || '' }}

Comment on lines 37 to 41

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

actions/checkout is given an empty ref for non-scheduled runs (... || ''). checkout expects a valid ref/SHA and an empty string can cause the step to fail. Use a non-empty fallback like github.ref/github.sha, or split into two checkout steps with if: github.event_name == 'schedule' and no ref override otherwise.

Suggested change
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'schedule' && 'staging' || '' }}
- name: Checkout (scheduled staging build)
if: github.event_name == 'schedule'
uses: actions/checkout@v4
with:
ref: staging
- name: Checkout
if: github.event_name != 'schedule'
uses: actions/checkout@v4

Copilot uses AI. Check for mistakes.
- name: Extract version from Cargo.toml
id: version
Expand All @@ -45,22 +51,35 @@ jobs:
run: |
VERSION="${{ steps.version.outputs.version }}"
SHA="sha-${GITHUB_SHA::7}"

Copilot AI Apr 3, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On schedule runs you checkout the staging branch, but SHA="sha-${GITHUB_SHA::7}" will still be the scheduled event SHA (default branch), not the checked-out staging commit. This will push misleading sha-... tags and also break any downstream logic that assumes the sha tag matches the built contents. Derive the SHA from the checked-out workspace (e.g., git rev-parse --short HEAD) for tagging (and for sha_tag).

Suggested change
SHA="sha-${GITHUB_SHA::7}"
SHORT_SHA="$(git rev-parse --short HEAD)"
SHA="sha-${SHORT_SHA}"

Copilot uses AI. Check for mistakes.
echo "sha_tag=${SHA}" >> "$GITHUB_OUTPUT"

if [[ "${{ github.event_name }}" == "workflow_call" ]]; then
# Release: :version + :latest + :sha-xxx
TAGS="${{ env.IMAGE_NAME }}:${VERSION}"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:latest"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:${VERSION}"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:latest"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${SHA}"
elif [[ "${{ github.event_name }}" == "schedule" ]]; then
# Daily staging: :staging + :sha-xxx
TAGS="${{ env.IMAGE_NAME }}:staging"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:staging"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${SHA}"
else
# Manual dispatch: :sha-xxx only
TAGS="${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:${SHA}"
fi

# Manual override adds an extra tag (e.g. "staging")
if [[ -n "${{ inputs.tag }}" ]]; then
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${{ inputs.tag }}"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${{ inputs.tag }}"
fi
echo "tags=${TAGS}" >> "$GITHUB_OUTPUT"
echo "worker_tags=${WORKER_TAGS}" >> "$GITHUB_OUTPUT"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
Expand All @@ -71,7 +90,7 @@ jobs:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}

- name: Build and push
- name: Build and push (ironclaw)
uses: docker/build-push-action@v6
with:
context: .
Expand All @@ -81,16 +100,32 @@ jobs:
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Build and push (ironclaw-worker)
uses: docker/build-push-action@v6
with:
context: .
file: Dockerfile.worker
push: true
tags: ${{ steps.tags.outputs.worker_tags }}
platforms: linux/amd64
cache-from: type=gha,scope=worker
cache-to: type=gha,mode=max,scope=worker

- name: Summary
run: |
{
echo "## Docker Image"
echo "## Docker Images"
echo ""
echo "**Tags pushed:**"
echo "**ironclaw:**"
echo '```'
echo "${{ steps.tags.outputs.tags }}" | tr ',' '\n'
Comment thread
Evrard-Nil marked this conversation as resolved.
echo '```'
echo ""
echo "**ironclaw-worker:**"
echo '```'
echo "${{ steps.tags.outputs.worker_tags }}" | tr ',' '\n'
Comment thread
Evrard-Nil marked this conversation as resolved.
echo '```'
echo ""
echo "- version: \`${{ steps.version.outputs.version }}\`"
echo "- sha: \`${GITHUB_SHA::7}\`"
} >> "$GITHUB_STEP_SUMMARY"
Loading