Publish container images with Gitea Actions
Some checks failed
Build and Publish Container / publish (push) Failing after 1m34s
Some checks failed
Build and Publish Container / publish (push) Failing after 1m34s
This commit is contained in:
44
.gitea/workflows/publish-container.yml
Normal file
44
.gitea/workflows/publish-container.yml
Normal file
@@ -0,0 +1,44 @@
|
||||
name: Build and Publish Container
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
tags:
|
||||
- "v*"
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
REGISTRY: gitea.dddbg.com
|
||||
IMAGE: gitea.dddbg.com/youbin/stun-nat
|
||||
steps:
|
||||
- name: Check out source
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Log in to Gitea Container Registry
|
||||
env:
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||
run: |
|
||||
test -n "$REGISTRY_TOKEN" || { echo "Missing Actions secret: REGISTRY_TOKEN"; exit 1; }
|
||||
printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY" --username youbin --password-stdin
|
||||
|
||||
- name: Build and push image
|
||||
run: |
|
||||
SHA_TAG="sha-${GITEA_SHA}"
|
||||
docker build --pull --tag "${IMAGE}:${SHA_TAG}" .
|
||||
docker push "${IMAGE}:${SHA_TAG}"
|
||||
|
||||
if [ "$GITEA_REF" = "refs/heads/main" ]; then
|
||||
docker tag "${IMAGE}:${SHA_TAG}" "${IMAGE}:latest"
|
||||
docker push "${IMAGE}:latest"
|
||||
fi
|
||||
|
||||
case "$GITEA_REF" in
|
||||
refs/tags/v*)
|
||||
docker tag "${IMAGE}:${SHA_TAG}" "${IMAGE}:${GITEA_REF_NAME}"
|
||||
docker push "${IMAGE}:${GITEA_REF_NAME}"
|
||||
;;
|
||||
esac
|
||||
@@ -49,6 +49,12 @@ docker compose up -d --build
|
||||
|
||||
运行后页面会显示 `公网映射 IP:端口`。该端口可能变化,应通过状态文件或后续 DDNS 集成同步域名记录。
|
||||
|
||||
## Gitea 镜像构建
|
||||
|
||||
`.gitea/workflows/publish-container.yml` 会在推送 `main` 或 `v*` 标签时构建并发布镜像到 `gitea.dddbg.com/youbin/stun-nat`。需要让带有 `ubuntu-latest` 标签、且可执行 Docker 的 Gitea Actions Runner 保持在线。
|
||||
|
||||
在仓库的 Actions Secrets 中创建 `REGISTRY_TOKEN`,其值为拥有 Gitea Package 写入权限的个人访问令牌。`main` 构建会发布 `latest` 与 `sha-<commit>` 标签;版本标签还会发布对应的 `v*` 标签。
|
||||
|
||||
## 公网可达性探针
|
||||
|
||||
STUN 成功证明映射已建立,但不能单独证明外部入站数据包当前仍可到达。需要严格验证时,将探针部署在与家庭网络不同的公网 VPS:
|
||||
|
||||
Reference in New Issue
Block a user