name: Build and Push Docker Images on: push: branches: [main] paths: - 'images/**' workflow_dispatch: inputs: image: description: 'Image to build (e.g., terraform-ci)' required: false env: REGISTRY: gitea.arnodo.fr jobs: # ============================================================================ # Job 1 : Détection des images modifiées # ============================================================================ detect-changes: runs-on: docker container: image: alpine:3.20 outputs: matrix: ${{ steps.changes.outputs.matrix }} has_changes: ${{ steps.changes.outputs.has_changes }} steps: - name: Install dependencies run: apk add --no-cache git jq - name: Checkout repository run: | git clone --depth 2 https://gitea.arnodo.fr/${{ gitea.repository }}.git . git checkout ${{ gitea.sha }} - name: Detect changed images id: changes run: | if [ -n "${{ inputs.image }}" ]; then # Manual trigger - build specific image echo "matrix=[\"${{ inputs.image }}\"]" >> $GITHUB_OUTPUT echo "has_changes=true" >> $GITHUB_OUTPUT else # Auto-detect changed images CHANGED=$(git diff --name-only HEAD~1 HEAD -- images/ 2>/dev/null | cut -d'/' -f2 | sort -u | grep -v '^$' || true) if [ -z "$CHANGED" ]; then echo "has_changes=false" >> $GITHUB_OUTPUT echo "matrix=[]" >> $GITHUB_OUTPUT else JSON=$(echo "$CHANGED" | jq -R -s -c 'split("\n") | map(select(length > 0))') echo "matrix=$JSON" >> $GITHUB_OUTPUT echo "has_changes=true" >> $GITHUB_OUTPUT fi fi - name: Show detected changes run: | echo "Matrix: ${{ steps.changes.outputs.matrix }}" echo "Has changes: ${{ steps.changes.outputs.has_changes }}" # ============================================================================ # Job 2 : Build avec Buildkit rootless (100% containerisé) # ============================================================================ build: needs: detect-changes if: needs.detect-changes.outputs.has_changes == 'true' runs-on: docker container: image: moby/buildkit:rootless options: --privileged strategy: matrix: image: ${{ fromJson(needs.detect-changes.outputs.matrix) }} steps: - name: Install git run: | # buildkit image is based on Alpine cat /etc/os-release || true apk add --no-cache git || apt-get update && apt-get install -y git || true - name: Checkout repository run: | git clone --depth 1 https://gitea.arnodo.fr/${{ gitea.repository }}.git /workspace cd /workspace git checkout ${{ gitea.sha }} || true - name: Build and push with Buildkit env: REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} REGISTRY_USER: ${{ gitea.actor }} run: | cd /workspace IMAGE_NAME="${{ env.REGISTRY }}/damien/${{ matrix.image }}" SHORT_SHA=$(echo "${{ gitea.sha }}" | cut -c1-7) # Create auth config for registry mkdir -p ~/.docker AUTH=$(echo -n "${REGISTRY_USER}:${REGISTRY_TOKEN}" | base64 | tr -d '\n') cat > ~/.docker/config.json <