Skip to content

chore(acp): track companion crates and correct the conformance record… #286

chore(acp): track companion crates and correct the conformance record…

chore(acp): track companion crates and correct the conformance record… #286

name: cd / canary container images
on:
push:
branches:
- main
concurrency:
group: canary-container-images-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: write
contents: read
id-token: write
packages: write
jobs:
build-and-push:
name: Build and push (${{ matrix.service }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
service:
- trogon-gateway
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Resolve service config
id: service_config
uses: ./.github/actions/resolve-service-config
with:
service: ${{ matrix.service }}
config-file: .github/canary-container-services.json
- name: Resolve image name
id: image
env:
IMAGE_OWNER: ${{ github.repository_owner }}
SERVICE_IMAGE: ${{ steps.service_config.outputs.image }}
run: ./.config/mise/tasks/github-actions/resolve-image
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
- name: Log in to GHCR
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push canary image
id: build_image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: ${{ steps.service_config.outputs.context }}
file: ${{ steps.service_config.outputs.dockerfile }}
push: true
tags: |
${{ steps.image.outputs.name }}:canary
${{ steps.image.outputs.name }}:sha-${{ steps.image.outputs.short_sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
sbom: true
provenance: mode=max
- name: Scan image for vulnerabilities
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: ${{ steps.image.outputs.name }}@${{ steps.build_image.outputs.digest }}
scanners: vuln
format: table
output: trivy-results.txt
ignore-unfixed: true
exit-code: 0
- name: Generate SBOM
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
with:
image: ${{ steps.image.outputs.name }}@${{ steps.build_image.outputs.digest }}
artifact-name: sbom-${{ matrix.service }}-spdx
format: spdx-json
- name: Document image security audit
shell: bash
env:
SERVICE: ${{ matrix.service }}
IMAGE_NAME: ${{ steps.image.outputs.name }}
IMAGE_DIGEST: ${{ steps.build_image.outputs.digest }}
RUNTIME_BASE: debian:bookworm-20260518-slim
run: ./.config/mise/tasks/github-actions/image-audit-summary