Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 67 additions & 0 deletions .github/actions/build-kit/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
name: Build kit
description: >-
Resolves a kit's pinned version, builds it multi-platform into a local OCI
layout, and validates it with kit-tck. Does not push — that's the caller's
job once this passes. Assumes the caller already checked out the repo.

inputs:
kit:
description: Kit name (a kits/<kit>/<kit>.yaml must exist)
required: true

outputs:
version:
description: The kit's pinned version, read from args.version.default
value: ${{ steps.kit.outputs.version }}
descriptor:
description: Path to the kit's descriptor, relative to the repo root
value: ${{ steps.kit.outputs.descriptor }}
layout:
description: Path to the exported OCI layout kit-tck validated
value: ${{ steps.build.outputs.layout }}

runs:
using: composite
steps:
# Installs yq and kit-tck per the repo's own mise.toml (see there for
# why kit-tck is pinned by GitHub release rather than a registry
# shorthand). This is the same mise this repo ships a sandbox kit for —
# dev tooling here uses it too rather than hand-rolling installs.
- uses: jdx/mise-action@v4

- id: kit
shell: bash
run: |
set -eu
descriptor="kits/${{ inputs.kit }}/${{ inputs.kit }}.yaml"
version="$(yq -r '.args.version.default' "$descriptor")"
if [ -z "$version" ] || [ "$version" = "null" ]; then
echo "no args.version.default in $descriptor" >&2
exit 1
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
echo "descriptor=$descriptor" >> "$GITHUB_OUTPUT"

- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3

# Multi-platform build, exported as an OCI layout (no registry needed)
# so kit-tck can judge every platform manifest before anything is
# published.
- id: build
shell: bash
run: |
set -eu
layout="/tmp/${{ inputs.kit }}-layout"
docker buildx build "kits/${{ inputs.kit }}" \
-f "${{ steps.kit.outputs.descriptor }}" \
--platform linux/amd64,linux/arm64 \
--cache-from "type=gha,scope=${{ inputs.kit }}" \
--cache-to "type=gha,scope=${{ inputs.kit }},mode=max" \
-t "${{ inputs.kit }}:${{ steps.kit.outputs.version }}" \
--output "type=oci,dest=${layout},tar=false"
echo "layout=$layout" >> "$GITHUB_OUTPUT"

- shell: bash
run: |
kit-tck validate --layout "${{ steps.build.outputs.layout }}" "${{ steps.kit.outputs.version }}"
23 changes: 23 additions & 0 deletions .github/actions/discover-kits/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: Discover kits
description: >-
Lists every kits/<name>/ directory that follows the companion-pair
convention (a kits/<name>/<name>.yaml descriptor).

outputs:
kits:
description: JSON array of kit names, e.g. ["mise"]
value: ${{ steps.discover.outputs.kits }}

runs:
using: composite
steps:
- id: discover
shell: bash
run: |
set -eu
kits=$(for d in kits/*/; do
name="$(basename "$d")"
[ -f "${d}${name}.yaml" ] && echo "$name"
done | jq -R -s -c 'split("\n") | map(select(length > 0))')
echo "Found kits: $kits"
echo "kits=$kits" >> "$GITHUB_OUTPUT"
65 changes: 65 additions & 0 deletions .github/workflows/publish-kits.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
name: Publish kits

on:
push:
branches: [main]
paths: ["kits/**", "mise.toml", ".github/actions/**", ".github/workflows/publish-kits.yml"]
workflow_dispatch: {}

concurrency:
group: publish-kits-${{ github.ref }}
cancel-in-progress: false

permissions:
contents: read
packages: write

jobs:
discover:
runs-on: ubuntu-24.04
outputs:
kits: ${{ steps.discover.outputs.kits }}
steps:
- uses: actions/checkout@v4
- id: discover
uses: ./.github/actions/discover-kits

publish:
needs: discover
if: needs.discover.outputs.kits != '[]'
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
kit: ${{ fromJson(needs.discover.outputs.kits) }}
steps:
- uses: actions/checkout@v4

# Same build + kit-tck gate as validate-kits.yml — a kit that fails
# conformance never reaches the push step below.
- id: build
uses: ./.github/actions/build-kit
with:
kit: ${{ matrix.kit }}

- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Push
run: |
# Several kits share this one repository, so the kit and its
# version live in the tag rather than the path: <kit>-<version> is
# the immutable reference, <kit> the moving tag consumers can pin
# past, matching docker/sandbox-kit-spec's RequireVersionedProvides.
repo="$(echo 'ghcr.io/${{ github.repository }}' | tr '[:upper:]' '[:lower:]')"
docker buildx build "kits/${{ matrix.kit }}" \
-f "${{ steps.build.outputs.descriptor }}" \
--platform linux/amd64,linux/arm64 \
--cache-from "type=gha,scope=${{ matrix.kit }}" \
--push \
-t "${repo}:${{ matrix.kit }}-${{ steps.build.outputs.version }}" \
-t "${repo}:${{ matrix.kit }}" \
--metadata-file "/tmp/${{ matrix.kit }}-push.json"
44 changes: 44 additions & 0 deletions .github/workflows/validate-kits.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: Validate kits

on:
pull_request:
paths: ["kits/**", "mise.toml", ".github/actions/**", ".github/workflows/validate-kits.yml"]
push:
branches-ignore: [main]
paths: ["kits/**", "mise.toml", ".github/actions/**", ".github/workflows/validate-kits.yml"]
workflow_dispatch: {}

concurrency:
group: validate-kits-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
discover:
runs-on: ubuntu-24.04
outputs:
kits: ${{ steps.discover.outputs.kits }}
steps:
- uses: actions/checkout@v4
- id: discover
uses: ./.github/actions/discover-kits

validate:
needs: discover
if: needs.discover.outputs.kits != '[]'
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
kit: ${{ fromJson(needs.discover.outputs.kits) }}
steps:
- uses: actions/checkout@v4

# Builds multi-platform, exports an OCI layout, and runs kit-tck
# against it — see .github/actions/build-kit. No push here; that only
# happens from publish-kits.yml, on main.
- uses: ./.github/actions/build-kit
with:
kit: ${{ matrix.kit }}
Loading
Loading