mirror of
https://github.com/element-hq/synapse.git
synced 2026-10-05 21:17:20 +00:00
Bumps the all-github-actions group with 2 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/build-push-action](https://github.com/docker/build-push-action). Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/docker/setup-buildx-action/releases">docker/setup-buildx-action's releases</a>.</em></p> <blockquote> <h2>v4.4.1</h2> <ul> <li>Skip BuildKit image pre-pulls for explicit endpoints by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/624">docker/setup-buildx-action#624</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1">https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1</a></p> <h2>v4.4.0</h2> <ul> <li>Use official Buildx releases for cloud driver by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/606">docker/setup-buildx-action#606</a></li> <li>Pull BuildKit image before builder creation by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/609">docker/setup-buildx-action#609</a></li> <li>Use shared error helpers for Buildx and Docker commands by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/620">docker/setup-buildx-action#620</a></li> <li>Bump <code>@docker/actions-toolkit</code> from 0.95.0 to 0.100.0 in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/610">docker/setup-buildx-action#610</a> <a href="https://redirect.github.com/docker/setup-buildx-action/pull/618">docker/setup-buildx-action#618</a> <a href="https://redirect.github.com/docker/setup-buildx-action/pull/619">docker/setup-buildx-action#619</a></li> <li>Bump <code>@humanfs/node</code> from 0.16.7 to 0.16.8 in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/614">docker/setup-buildx-action#614</a></li> <li>Bump js-yaml from 5.3.0 to 5.4.2 in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/608">docker/setup-buildx-action#608</a> <a href="https://redirect.github.com/docker/setup-buildx-action/pull/617">docker/setup-buildx-action#617</a></li> <li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a href="https://redirect.github.com/docker/setup-buildx-action/pull/611">docker/setup-buildx-action#611</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0">https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069"><code>f87e599</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-buildx-action/issues/624">#624</a> from crazy-max/skip-pull-with-endpoint</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022"><code>e700274</code></a> chore: update generated content</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07"><code>3061c91</code></a> skip BuildKit image pre-pulls for explicit endpoints</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003"><code>594f3bf</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-buildx-action/issues/609">#609</a> from crazy-max/pull-buildkit-image-before-create</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25"><code>bd6e702</code></a> chore: update generated content</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032"><code>6268c9d</code></a> pull BuildKit image before builder creation</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11"><code>e823525</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-buildx-action/issues/621">#621</a> from docker/dependabot/github_actions/codeql-actions-...</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d"><code>533ed8e</code></a> build(deps): bump the codeql-actions group with 2 updates</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99"><code>bedaf13</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-buildx-action/issues/620">#620</a> from crazy-max/shared-error-helpers</li> <li><a href="https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2"><code>d5079fb</code></a> chore: update generated content</li> <li>Additional commits viewable in <a href="https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...f87e5991a6d7451dcb8d9637bfbc97413f497069">compare view</a></li> </ul> </details> <br /> Updates `docker/build-push-action` from 7.3.0 to 7.4.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/docker/build-push-action/releases">docker/build-push-action's releases</a>.</em></p> <blockquote> <h2>v7.4.0</h2> <ul> <li>Use the shared error helper for Buildx commands by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/build-push-action/pull/1620">docker/build-push-action#1620</a></li> <li>Prevent workflow command injection in metadata logs by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/build-push-action/pull/1617">docker/build-push-action#1617</a></li> <li>Bump <code>@docker/actions-toolkit</code> from 0.92.0 to 0.100.0 in <a href="https://redirect.github.com/docker/build-push-action/pull/1614">docker/build-push-action#1614</a> <a href="https://redirect.github.com/docker/build-push-action/pull/1618">docker/build-push-action#1618</a> <a href="https://redirect.github.com/docker/build-push-action/pull/1621">docker/build-push-action#1621</a></li> <li>Bump <code>@humanfs/node</code> from 0.16.7 to 0.16.8 in <a href="https://redirect.github.com/docker/build-push-action/pull/1609">docker/build-push-action#1609</a></li> <li>Bump brace-expansion from 1.1.13 to 1.1.18 in <a href="https://redirect.github.com/docker/build-push-action/pull/1592">docker/build-push-action#1592</a></li> <li>Bump csv-parse from 7.0.0 to 7.0.2 in <a href="https://redirect.github.com/docker/build-push-action/pull/1613">docker/build-push-action#1613</a></li> <li>Bump js-yaml from 4.3.0 to 4.3.2 in <a href="https://redirect.github.com/docker/build-push-action/pull/1605">docker/build-push-action#1605</a> <a href="https://redirect.github.com/docker/build-push-action/pull/1615">docker/build-push-action#1615</a></li> <li>Bump nanoid from 3.3.16 to 3.3.18 in <a href="https://redirect.github.com/docker/build-push-action/pull/1611">docker/build-push-action#1611</a></li> <li>Bump postcss from 8.5.10 to 8.5.25 in <a href="https://redirect.github.com/docker/build-push-action/pull/1590">docker/build-push-action#1590</a></li> <li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a href="https://redirect.github.com/docker/build-push-action/pull/1606">docker/build-push-action#1606</a></li> <li>Bump sigstore from 4.1.0 to 4.1.1 in <a href="https://redirect.github.com/docker/build-push-action/pull/1577">docker/build-push-action#1577</a></li> <li>Bump undici from 6.27.0 to 6.28.0 in <a href="https://redirect.github.com/docker/build-push-action/pull/1594">docker/build-push-action#1594</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0">https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc"><code>c3c9e26</code></a> Merge pull request <a href="https://redirect.github.com/docker/build-push-action/issues/1621">#1621</a> from docker/dependabot/npm_and_yarn/docker/actions-t...</li> <li><a href="https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42"><code>459b674</code></a> [dependabot skip] chore: update generated content</li> <li><a href="https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e"><code>4dedcb2</code></a> chore(deps): Bump <code>@docker/actions-toolkit</code> from 0.99.0 to 0.100.0</li> <li><a href="https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952"><code>379bf63</code></a> Merge pull request <a href="https://redirect.github.com/docker/build-push-action/issues/1620">#1620</a> from crazy-max/buildx-error-message</li> <li><a href="https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6"><code>9877975</code></a> chore: update generated content</li> <li><a href="https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94"><code>7ed0556</code></a> use the shared Buildx error summary helper</li> <li><a href="https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1"><code>91670ba</code></a> Merge pull request <a href="https://redirect.github.com/docker/build-push-action/issues/1618">#1618</a> from docker/dependabot/npm_and_yarn/docker/actions-t...</li> <li><a href="https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a"><code>80dbc86</code></a> [dependabot skip] chore: update generated content</li> <li><a href="https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d"><code>50cac3a</code></a> chore(deps): Bump <code>@docker/actions-toolkit</code> from 0.98.0 to 0.99.0</li> <li><a href="https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1"><code>03b4d6c</code></a> Merge pull request <a href="https://redirect.github.com/docker/build-push-action/issues/1617">#1617</a> from crazy-max/fix-metadata-workflow-commands</li> <li>Additional commits viewable in <a href="https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
222 lines
8.4 KiB
YAML
222 lines
8.4 KiB
YAML
# GitHub actions workflow which builds and publishes the docker images.
|
|
|
|
name: Build docker images
|
|
|
|
on:
|
|
push:
|
|
tags: ["v*"]
|
|
branches: [master, main, develop]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
id-token: write # needed for signing the images with GitHub OIDC Token
|
|
jobs:
|
|
build:
|
|
name: Build and push image for ${{ matrix.platform }}
|
|
runs-on: ${{ matrix.runs_on }}
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- platform: linux/amd64
|
|
runs_on: ubuntu-24.04
|
|
suffix: linux-amd64
|
|
- platform: linux/arm64
|
|
runs_on: ubuntu-24.04-arm
|
|
suffix: linux-arm64
|
|
steps:
|
|
- name: Set up Docker Buildx
|
|
id: buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
- name: Extract version from pyproject.toml
|
|
# Note: explicitly requesting bash will mean bash is invoked with `-eo pipefail`, see
|
|
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsshell
|
|
shell: bash
|
|
run: |
|
|
echo "SYNAPSE_VERSION=$(grep "^version" pyproject.toml | sed -E 's/version\s*=\s*["]([^"]*)["]/\1/')" >> $GITHUB_ENV
|
|
|
|
- name: Log in to DockerHub
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.repository_owner }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Tailscale
|
|
uses: tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd # v4.2.0
|
|
with:
|
|
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
|
|
audience: ${{ secrets.TS_AUDIENCE }}
|
|
tags: tag:github-actions
|
|
|
|
- name: Compute vault jwt role name
|
|
id: vault-jwt-role
|
|
run: |
|
|
echo "role_name=github_service_management_$( echo "${{ github.repository }}" | sed -r 's|[/-]|_|g')" | tee -a "$GITHUB_OUTPUT"
|
|
|
|
- name: Get team registry token
|
|
id: import-secrets
|
|
uses: hashicorp/vault-action@892a26828f195e65540a40b4768ae4571f51ebfc # v4.0.0
|
|
with:
|
|
url: https://vault.infra.ci.i.element.dev
|
|
role: ${{ steps.vault-jwt-role.outputs.role_name }}
|
|
path: service-management/github-actions
|
|
jwtGithubAudience: https://vault.infra.ci.i.element.dev
|
|
method: jwt
|
|
secrets: |
|
|
services/backend-repositories/secret/data/oci.element.io username | OCI_USERNAME ;
|
|
services/backend-repositories/secret/data/oci.element.io password | OCI_PASSWORD ;
|
|
|
|
- name: Login to Element OCI Registry
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
registry: oci-push.vpn.infra.element.io
|
|
username: ${{ steps.import-secrets.outputs.OCI_USERNAME }}
|
|
password: ${{ steps.import-secrets.outputs.OCI_PASSWORD }}
|
|
|
|
- name: Build and push by digest
|
|
id: build
|
|
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
|
with:
|
|
push: true
|
|
labels: |
|
|
gitsha1=${{ github.sha }}
|
|
org.opencontainers.image.version=${{ env.SYNAPSE_VERSION }}
|
|
tags: |
|
|
docker.io/matrixdotorg/synapse
|
|
ghcr.io/element-hq/synapse
|
|
oci-push.vpn.infra.element.io/synapse
|
|
file: "docker/Dockerfile"
|
|
platforms: ${{ matrix.platform }}
|
|
outputs: type=image,push-by-digest=true,name-canonical=true,push=true
|
|
|
|
- name: Export digest
|
|
run: |
|
|
mkdir -p ${{ runner.temp }}/digests
|
|
digest="${{ steps.build.outputs.digest }}"
|
|
touch "${{ runner.temp }}/digests/${digest#sha256:}"
|
|
|
|
- name: Upload digest
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: digests-${{ matrix.suffix }}
|
|
path: ${{ runner.temp }}/digests/*
|
|
if-no-files-found: error
|
|
retention-days: 1
|
|
|
|
merge:
|
|
name: Push merged images to ${{ matrix.repository }}
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
repository:
|
|
- docker.io/matrixdotorg/synapse
|
|
- ghcr.io/element-hq/synapse
|
|
- oci-push.vpn.infra.element.io/synapse
|
|
|
|
needs:
|
|
- build
|
|
steps:
|
|
- name: Download digests
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
path: ${{ runner.temp }}/digests
|
|
pattern: digests-*
|
|
merge-multiple: true
|
|
|
|
- name: Log in to DockerHub
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
if: ${{ startsWith(matrix.repository, 'docker.io') }}
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
if: ${{ startsWith(matrix.repository, 'ghcr.io') }}
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.repository_owner }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Tailscale
|
|
uses: tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd # v4.2.0
|
|
with:
|
|
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
|
|
audience: ${{ secrets.TS_AUDIENCE }}
|
|
tags: tag:github-actions
|
|
|
|
- name: Compute vault jwt role name
|
|
id: vault-jwt-role
|
|
run: |
|
|
echo "role_name=github_service_management_$( echo "${{ github.repository }}" | sed -r 's|[/-]|_|g')" | tee -a "$GITHUB_OUTPUT"
|
|
|
|
- name: Get team registry token
|
|
id: import-secrets
|
|
uses: hashicorp/vault-action@892a26828f195e65540a40b4768ae4571f51ebfc # v4.0.0
|
|
with:
|
|
url: https://vault.infra.ci.i.element.dev
|
|
role: ${{ steps.vault-jwt-role.outputs.role_name }}
|
|
path: service-management/github-actions
|
|
jwtGithubAudience: https://vault.infra.ci.i.element.dev
|
|
method: jwt
|
|
secrets: |
|
|
services/backend-repositories/secret/data/oci.element.io username | OCI_USERNAME ;
|
|
services/backend-repositories/secret/data/oci.element.io password | OCI_PASSWORD ;
|
|
|
|
- name: Login to Element OCI Registry
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
registry: oci-push.vpn.infra.element.io
|
|
username: ${{ steps.import-secrets.outputs.OCI_USERNAME }}
|
|
password: ${{ steps.import-secrets.outputs.OCI_PASSWORD }}
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
|
|
|
|
- name: Install Cosign
|
|
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
|
|
- name: Calculate docker image tag
|
|
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
|
|
with:
|
|
images: ${{ matrix.repository }}
|
|
flavor: |
|
|
latest=false
|
|
tags: |
|
|
type=raw,value=develop,enable=${{ github.ref == 'refs/heads/develop' }}
|
|
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/master' }}
|
|
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }}
|
|
type=pep440,pattern={{raw}}
|
|
type=sha
|
|
|
|
- name: Create manifest list and push
|
|
working-directory: ${{ runner.temp }}/digests
|
|
env:
|
|
REPOSITORY: ${{ matrix.repository }}
|
|
run: |
|
|
docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \
|
|
$(printf "$REPOSITORY@sha256:%s " *)
|
|
|
|
- name: Sign each manifest
|
|
env:
|
|
REPOSITORY: ${{ matrix.repository }}
|
|
run: |
|
|
DIGESTS=""
|
|
for TAG in $(echo "$DOCKER_METADATA_OUTPUT_JSON" | jq -r '.tags[]'); do
|
|
DIGEST="$(docker buildx imagetools inspect $TAG --format '{{json .Manifest}}' | jq -r '.digest')"
|
|
DIGESTS="$DIGESTS $REPOSITORY@$DIGEST"
|
|
done
|
|
cosign sign --yes $DIGESTS
|