mirror of
https://github.com/temporalio/temporal.git
synced 2026-08-30 18:41:49 -07:00
## What changed? * updates goreleaser to v2 * add GHA for build admin-tools and server images within this repo. `docker-builds` will only be used for building pre 1.30 images * added GHA to promote docker builds from temporaliotest to temproalio docker image repos * trivy security scanning gates for image promotion (pulled rom docker-builds repo). The gate can be overridden ## Why? * we decided to move away from building images in `docker-builds`. The complexity is not needed * updates goreleaser to v2 because the v1 definitions might be no longer supported at some point and this is a good time to do it * I used go scripts for the more complex flows instead of js or bash so we don't introduce another language contributors need to be familiar with. IMO the js or bash I did use it simple enough to understand. ## How did you test it? It passes in CI. ## Potential risks * these build pipelines are only compatible with the new docker images. * merging this PR may break our nightly tests. Will double check before merging * flows that are not triggered by opening a PR are untested and therefore not completely validated
32 lines
933 B
YAML
32 lines
933 B
YAML
name: Promote Server Image
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
source-tag:
|
|
description: "Source tag from temporaliotest registry (e.g. sha-abc123)"
|
|
required: true
|
|
target-tags:
|
|
description: "Target tags for temporalio registry (comma or newline separated, e.g., 1.29.1, latest)"
|
|
required: true
|
|
override-security-scan:
|
|
description: "Override security scan failures (use with caution)"
|
|
type: boolean
|
|
default: false
|
|
required: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
promote:
|
|
uses: ./.github/workflows/promote-docker-image.yml
|
|
with:
|
|
image-name: server
|
|
source-tag: ${{ inputs.source-tag }}
|
|
target-tags: ${{ inputs.target-tags }}
|
|
override-security-scan: ${{ inputs.override-security-scan }}
|
|
secrets:
|
|
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
|