# Build and Push Docker Images # Runs on every push to main branch # 1. Lint: Black, Ruff, MyPy # 2. Build & Push: Docker images to registry name: Build on: push: branches: [ main ] env: POETRY_VERSION: 1.8.0 PYTHON_VERSION: "3.12" REGISTRY: ${{ vars.PACKAGES_REGISTRY }} IMAGE_NAME: ${{ gitea.repository }} jobs: lint: name: Code Quality Checks runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Python uses: actions/setup-python@v5 with: python-version: ${{ env.PYTHON_VERSION }} cache: 'pip' - name: Install Poetry run: | curl -sSL https://install.python-poetry.org | python3 - echo "$HOME/.local/bin" >> $GITHUB_PATH - name: Install dependencies run: | poetry config virtualenvs.in-project true poetry install --no-root - name: Run Black run: poetry run black --check src/ tests/ - name: Run Ruff run: poetry run ruff check src/ tests/ - name: Run MyPy run: poetry run mypy src/ build-and-push: name: Build & Push Docker Images runs-on: ubuntu-latest needs: lint strategy: matrix: component: [api, chat, worker, frontend] steps: - name: Checkout code uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to Container Registry uses: docker/login-action@v3 with: registry: ${{ vars.PACKAGES_REGISTRY }} username: ${{ secrets.USERNAME }} password: ${{ secrets.TOKEN }} - name: Extract metadata id: meta uses: docker/metadata-action@v5 with: images: ${{ vars.PACKAGES_REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.component }} tags: | type=ref,event=branch type=sha,prefix={{branch}}- type=raw,value=latest - name: Build and push Docker image uses: docker/build-push-action@v5 with: context: . file: deploy/docker/Dockerfile.${{ matrix.component }} push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=registry,ref=${{ vars.PACKAGES_REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.component }}:buildcache cache-to: type=registry,ref=${{ vars.PACKAGES_REGISTRY }}/${{ env.IMAGE_NAME }}/${{ matrix.component }}:buildcache,mode=max