name: build-hello-app on: push: branches: [main] paths: - "apps/hello-app/src/**" jobs: build-and-push: runs-on: docker # kaniko builds the image itself with no daemon and no special host # privileges, so the runner host only ever needs a rootless Podman # socket to launch this container — never docker.sock, never sudo. container: image: gcr.io/kaniko-project/executor:debug options: --entrypoint "" steps: - uses: actions/checkout@v4 - name: Write registry auth run: | mkdir -p /kaniko/.docker AUTH=$(printf '%s:%s' "${{ vars.FORGEJO_USER }}" "${{ secrets.FORGEJO_TOKEN }}" | base64 -w0) printf '{"auths":{"git.boglabob.com":{"auth":"%s"}}}' "$AUTH" > /kaniko/.docker/config.json - name: Inject build info run: | SHORT_SHA="${GITHUB_SHA::7}" BUILD_TIME=$(date -u +%Y-%m-%dT%H:%M:%SZ) sed -i "s/__GIT_SHA__/$SHORT_SHA/; s/__BUILD_TIME__/$BUILD_TIME/" apps/hello-app/src/index.html - name: Build and push run: | TAG="main-${GITHUB_SHA::7}-$(date +%s)" /kaniko/executor \ --context="${{ github.workspace }}/apps/hello-app/src" \ --dockerfile="${{ github.workspace }}/apps/hello-app/src/Dockerfile" \ --destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:$TAG" \ --destination="git.boglabob.com/${{ vars.FORGEJO_ORG }}/hello-app:latest"