name: Build and Push Docker Images on: push: branches: [main] paths: - 'images/**' workflow_dispatch: inputs: image: description: 'Image to build (e.g., terraform-ci)' required: false env: REGISTRY: gitea.arnodo.fr jobs: # ============================================================================ # Job 1 : Détection des images modifiées # ============================================================================ detect-changes: runs-on: docker container: image: alpine:3.20 outputs: matrix: ${{ steps.changes.outputs.matrix }} has_changes: ${{ steps.changes.outputs.has_changes }} steps: - name: Install dependencies run: apk add --no-cache git jq - name: Checkout repository run: | git clone --depth 2 https://gitea.arnodo.fr/${{ gitea.repository }}.git . git checkout ${{ gitea.sha }} - name: Detect changed images id: changes run: | if [ -n "${{ inputs.image }}" ]; then echo "matrix=[\"${{ inputs.image }}\"]" >> $GITHUB_OUTPUT echo "has_changes=true" >> $GITHUB_OUTPUT else CHANGED=$(git diff --name-only HEAD~1 HEAD -- images/ 2>/dev/null | cut -d'/' -f2 | sort -u | grep -v '^$' || true) if [ -z "$CHANGED" ]; then echo "has_changes=false" >> $GITHUB_OUTPUT echo "matrix=[]" >> $GITHUB_OUTPUT else JSON=$(echo "$CHANGED" | jq -R -s -c 'split("\n") | map(select(length > 0))') echo "matrix=$JSON" >> $GITHUB_OUTPUT echo "has_changes=true" >> $GITHUB_OUTPUT fi fi - name: Show detected changes run: | echo "Matrix: ${{ steps.changes.outputs.matrix }}" echo "Has changes: ${{ steps.changes.outputs.has_changes }}" # ============================================================================ # Job 2 : Build avec Kaniko (100% containerisé, sans daemon Docker) # ============================================================================ build: needs: detect-changes if: needs.detect-changes.outputs.has_changes == 'true' runs-on: docker container: image: gcr.io/kaniko-project/executor:debug strategy: matrix: image: ${{ fromJson(needs.detect-changes.outputs.matrix) }} steps: - name: Checkout repository run: | # Kaniko debug image has busybox + sh WORK_DIR="/workspace/source" rm -rf "$WORK_DIR" mkdir -p "$WORK_DIR" # Clone with git (included in debug image) git clone --depth 1 https://gitea.arnodo.fr/${{ gitea.repository }}.git "$WORK_DIR" - name: Setup registry auth env: REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} REGISTRY_USER: ${{ gitea.actor }} run: | mkdir -p /kaniko/.docker AUTH=$(echo -n "${REGISTRY_USER}:${REGISTRY_TOKEN}" | base64 | tr -d '\n') cat > /kaniko/.docker/config.json <