#!/usr/bin/env bash # Builds the production image from the current main state and pushes it to the # Gitea registry, tagged with :latest AND the short commit SHA (rollback). # # For approved states only: the script refuses to push if you are not on main # or have uncommitted changes. For dev builds without a push use # scripts/dev-build.sh instead. # # Prerequisite: a one-time `docker login gitea.anticarnist.de` (see # docs/deployment.md). set -euo pipefail IMAGE="gitea.anticarnist.de/tom/elternbeirat" # Change into the repo root (the script lives in scripts/) so the Docker build # context is correct no matter where it is called from. cd "$(dirname "$0")/.." branch="$(git rev-parse --abbrev-ref HEAD)" if [[ "$branch" != "main" ]]; then echo "ABORT: you are on '$branch', not on 'main'." >&2 echo "A :latest release may only be built from main." >&2 echo "For a dev build without a push: scripts/dev-build.sh" >&2 exit 1 fi if [[ -n "$(git status --porcelain)" ]]; then echo "ABORT: working tree is not clean (uncommitted changes)." >&2 echo "Commit first so the SHA tag names the image content unambiguously." >&2 exit 1 fi # Warn if the local main is ahead of the remote (unpushed commits) -- otherwise # a SHA would be tagged that does not yet exist on Gitea. if git rev-parse --verify --quiet origin/main >/dev/null; then ahead="$(git rev-list --count origin/main..HEAD)" if [[ "$ahead" -gt 0 ]]; then echo "WARNING: local main is ahead of origin/main by $ahead commit(s)." >&2 echo " Run 'git push' first so the SHA exists on Gitea." >&2 read -r -p "Continue anyway? [y/N] " answer [[ "$answer" == "y" || "$answer" == "Y" ]] || exit 1 fi fi sha="$(git rev-parse --short HEAD)" echo "Building $IMAGE (tags: latest, $sha)" docker build -t "$IMAGE:latest" -t "$IMAGE:$sha" . docker push "$IMAGE" --all-tags echo echo "Done. Pushed: $IMAGE:latest and $IMAGE:$sha" echo "On Unraid: stack 'elternbeirat' -> Compose Down/Up (or Pull) so the new" echo ":latest is fetched."