diff --git a/.forgejo/workflows/build-hello-app.yml b/.forgejo/workflows/build-hello-app.yml index 14ccc5a..af2827b 100644 --- a/.forgejo/workflows/build-hello-app.yml +++ b/.forgejo/workflows/build-hello-app.yml @@ -15,6 +15,8 @@ jobs: container: image: gcr.io/kaniko-project/executor:debug options: --entrypoint "" + outputs: + tag: ${{ steps.build.outputs.tag }} steps: # actions/checkout@v4 needs a Node.js runtime, which this minimal # kaniko image doesn't have (no package manager to add it either) - @@ -43,10 +45,40 @@ jobs: sed -i "s/__GIT_SHA__/$SHORT_SHA/; s/__BUILD_TIME__/$BUILD_TIME/" apps/hello-app/src/index.html - name: Build and push + id: build run: | TAG="main-${GITHUB_SHA::7}-$(date +%s)" + echo "tag=$TAG" >> "$GITHUB_OUTPUT" /kaniko/executor \ --context="${{ github.workspace }}/apps/hello-app/src" \ --dockerfile="${{ github.workspace }}/apps/hello-app/src/Dockerfile" \ --destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:$TAG" \ --destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:latest" + + # Flux's ImageUpdateAutomation (image-automation.yaml) should be doing this + # commit-back step instead - its $imagepolicy Setters marker in + # deployment.yaml is correctly formatted and verified against Flux's own + # docs, ImagePolicy correctly resolves each new tag, and every other part + # of the chain works, but it never actually commits (always reports + # "repository up-to-date" with nothing to change) for reasons that + # resisted a lengthy investigation - even a from-scratch Flux bootstrap + # against a fresh controller instance didn't change the behavior. + # ImageRepository/ImagePolicy are kept for visibility into what tag is + # available; this job does the actual commit as a working substitute. + update-deployment-tag: + needs: build-and-push + runs-on: docker + container: + image: alpine/git + steps: + - name: Commit new image tag to deployment.yaml + run: | + git config --global user.email "flux@boglabob.com" + git config --global user.name "fluxcdbot" + git clone "https://${{ vars.FORGEJO_USER }}:${{ secrets.FORGEJO_TOKEN }}@git.boglabob.com/${{ github.repository }}.git" repo + cd repo + TAG="${{ needs.build-and-push.outputs.tag }}" + sed -i "s|\(image: git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:\)[^ ]*|\1$TAG|" apps/hello-app/deployment.yaml + git add apps/hello-app/deployment.yaml + git diff --cached --quiet || git commit -m "chore(hello-app): auto-update image to $TAG" + git push