name: Build Next Image on: push: branches: - main concurrency: group: build-next-image cancel-in-progress: true jobs: build-next: runs-on: ubuntu-latest permissions: contents: read packages: write id-token: write attestations: write steps: - name: Checkout code uses: actions/checkout@v5 - name: Setup pnpm uses: pnpm/action-setup@v4 - name: Setup Node.js uses: actions/setup-node@v5 with: node-version: 22 - name: Setup Go uses: actions/setup-go@v6 with: go-version-file: "backend/go.mod" - name: Set up QEMU uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Set DOCKER_IMAGE_NAME run: | # Lowercase REPO_OWNER which is required for containers REPO_OWNER=${{ github.repository_owner }} DOCKER_IMAGE_NAME="ghcr.io/${REPO_OWNER,,}/pocket-id" echo "DOCKER_IMAGE_NAME=${DOCKER_IMAGE_NAME}" >>${GITHUB_ENV} - name: Login to GitHub Container Registry uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.repository_owner }} password: ${{ secrets.GITHUB_TOKEN }} - name: Install frontend dependencies run: pnpm install --frozen-lockfile - name: Build frontend working-directory: frontend run: pnpm run build - name: Build binaries run: sh scripts/development/build-binaries.sh --docker-only - name: Build and push container image id: build-push-image uses: docker/build-push-action@v6 with: context: . platforms: linux/amd64,linux/arm64 push: true tags: ${{ env.DOCKER_IMAGE_NAME }}:next file: docker/Dockerfile-prebuilt - name: Build and push container image (distroless) uses: docker/build-push-action@v6 id: container-build-push-distroless with: context: . platforms: linux/amd64,linux/arm64 push: true tags: ${{ env.DOCKER_IMAGE_NAME }}:next-distroless file: docker/Dockerfile-distroless - name: Container image attestation uses: actions/attest-build-provenance@v2 with: subject-name: "${{ env.DOCKER_IMAGE_NAME }}" subject-digest: ${{ steps.build-push-image.outputs.digest }} push-to-registry: true - name: Container image attestation (distroless) uses: actions/attest-build-provenance@v2 with: subject-name: "${{ env.DOCKER_IMAGE_NAME }}" subject-digest: ${{ steps.container-build-push-distroless.outputs.digest }} push-to-registry: true