Skip to content

Publish cnspec container with providers #190

Publish cnspec container with providers

Publish cnspec container with providers #190

Workflow file for this run

name: Publish cnspec container with providers
on:
repository_dispatch:
types: [update]
workflow_dispatch:
inputs:
version:
description: 'Version of the cnspec container to publish'
type: string
required: false
default: 'latest'
env:
GHCR_IMAGE: ghcr.io/mondoohq/mondoo-operator/cnspec
GCP_IMAGE: us-docker.pkg.dev/mondoohq/release/mondoo-operator-cnspec
jobs:
build-cnspec:
name: Build cnspec container
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
matrix:
suffix:
- ""
- -ubi
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Sanitize version input (Workflow Dispatch)
if: github.event_name == 'workflow_dispatch'
run: |
TAG=${{ github.event.inputs.version }}
echo "VERSION=${TAG#v}" >> $GITHUB_ENV
- name: Sanitize version input (Repository Dispatch)
if: github.event_name == 'repository_dispatch'
run: |
TAG=${{ github.event.client_payload.version }}
echo "VERSION=${TAG#v}" >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log into registry ghcr.io
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Authenticate with Google Cloud
uses: "google-github-actions/auth@v2"
with:
credentials_json: "${{ secrets.GCP_ARTIFACT_REGISTRY_SA }}"
- name: "Set up Cloud SDK"
uses: "google-github-actions/setup-gcloud@v2"
- name: Docker Login (GCR)
run: |
gcloud auth configure-docker us-docker.pkg.dev
- name: "Setup Docker Buildx"
uses: docker/setup-buildx-action@v3
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
with:
images: |
${{ env.GHCR_IMAGE }}
${{ env.GCP_IMAGE }}
tags: |
type=semver,pattern={{version}},value=${{ env.VERSION }}
type=semver,pattern={{major}},value=${{ env.VERSION }}
type=raw,value=latest
flavor: |
suffix=${{ matrix.suffix }}-rootless,onlatest=true
- name: Build and push cnspec image
id: build-and-push-operator
uses: docker/build-push-action@v6
with:
context: .
file: cnspec.Dockerfile
build-args: VERSION=${{ env.VERSION }}${{ matrix.suffix }}
platforms: linux/amd64,linux/arm64
push: true
labels: ${{ steps.meta.outputs.labels }}
tags: ${{ steps.meta.outputs.tags }}