name: Build and Publish Container on: push: branches: - main tags: - "v*" workflow_dispatch: jobs: publish: runs-on: ubuntu-latest env: REGISTRY: gitea.dddbg.com IMAGE: gitea.dddbg.com/youbin/stun-nat steps: - name: Check out source uses: actions/checkout@v4 - name: Log in to Gitea Container Registry env: REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | test -n "$REGISTRY_TOKEN" || { echo "Missing Actions secret: REGISTRY_TOKEN"; exit 1; } printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY" --username youbin --password-stdin - name: Build and push image run: | docker run --privileged --rm tonistiigi/binfmt --install arm64 BUILDER="stun-nat-${GITHUB_RUN_ID}" docker buildx create --driver docker-container --name "$BUILDER" --use trap 'docker buildx rm "$BUILDER"' EXIT docker buildx inspect --bootstrap build_and_push() { local attempt=1 until docker buildx build --platform linux/amd64,linux/arm64 --pull --push "${TAGS[@]}" .; do if [ "$attempt" -ge 3 ]; then echo "Failed to build and publish multi-architecture image after ${attempt} attempts" return 1 fi attempt=$((attempt + 1)) echo "Build or push failed; retrying (${attempt}/3) in 10 seconds" sleep 10 done } SHA_TAG="sha-${GITHUB_SHA}" TAGS=(--tag "${IMAGE}:${SHA_TAG}") if [ "$GITHUB_REF" = "refs/heads/main" ]; then TAGS+=(--tag "${IMAGE}:latest") fi case "$GITHUB_REF" in refs/tags/v*) TAGS+=(--tag "${IMAGE}:${GITHUB_REF_NAME}") ;; esac build_and_push