# Builds the production image on every push to main and pushes it to the Gitea # registry, tagged with :latest AND the short commit SHA (for rollback) -- the # same tagging scheme as scripts/release.sh, but run by the act_runner instead # of by hand. # # It does NOT deploy: pulling and starting the new :latest on Unraid stays a # manual, deliberate step (Compose Down/Up). Auto-deploy via Watchtower is an # open item in docs/deployment.md and needs a health gate first, so a broken # page can never go live unnoticed. # # Required repository secrets (Gitea -> repo -> Settings -> Actions -> Secrets): # REGISTRY_USER the registry username (e.g. Tom) # REGISTRY_TOKEN a Gitea access token with package:write -- NOT the password name: Build and push image on: push: branches: [main] env: IMAGE: gitea.anticarnist.de/tom/elternbeirat jobs: build: runs-on: ubuntu-latest steps: - name: Check out the source uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to the Gitea registry uses: docker/login-action@v3 with: registry: gitea.anticarnist.de username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_TOKEN }} # The short SHA names the image content unambiguously and never moves, # so it is the stable handle for a rollback. - name: Compute the short commit SHA id: sha run: echo "short=$(git rev-parse --short HEAD)" >> "$GITHUB_OUTPUT" - name: Build and push (:latest and :) uses: docker/build-push-action@v6 with: context: . push: true tags: | ${{ env.IMAGE }}:latest ${{ env.IMAGE }}:${{ steps.sha.outputs.short }}