Files
temporal/.github/workflows/promote-admin-tools-image.yml
Alex Stanfield 85635674d7 New Docker Build GH Actions (#8825)
## What changed?
* updates goreleaser to v2
* add GHA for build admin-tools and server images within this repo.
`docker-builds` will only be used for building pre 1.30 images
* added GHA to promote docker builds from temporaliotest to temproalio
docker image repos
* trivy security scanning gates for image promotion (pulled rom
docker-builds repo). The gate can be overridden

## Why?
* we decided to move away from building images in `docker-builds`. The
complexity is not needed
* updates goreleaser to v2 because the v1 definitions might be no longer
supported at some point and this is a good time to do it
* I used go scripts for the more complex flows instead of js or bash so
we don't introduce another language contributors need to be familiar
with. IMO the js or bash I did use it simple enough to understand.

## How did you test it?
It passes in CI. 

## Potential risks
* these build pipelines are only compatible with the new docker images. 
* merging this PR may break our nightly tests. Will double check before
merging
* flows that are not triggered by opening a PR are untested and
therefore not completely validated
2025-12-18 20:30:58 +00:00

32 lines
943 B
YAML

name: Promote Admin Tools Image
on:
workflow_dispatch:
inputs:
source-tag:
description: "Source tag from temporaliotest registry (e.g. sha-abc123)"
required: true
target-tags:
description: "Target tags for temporalio registry (comma or newline separated, e.g., 1.29.1, latest)"
required: true
override-security-scan:
description: "Override security scan failures (use with caution)"
type: boolean
default: false
required: false
permissions:
contents: read
jobs:
promote:
uses: ./.github/workflows/promote-docker-image.yml
with:
image-name: admin-tools
source-tag: ${{ inputs.source-tag }}
target-tags: ${{ inputs.target-tags }}
override-security-scan: ${{ inputs.override-security-scan }}
secrets:
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}