--- # CI job images: stage each Containerfile, restore the image from the Gitea # registry if the nightly prune removed it, rebuild only when the Containerfile # changed, then push so the registry always holds what the runner uses. # See gitea_ci_images in defaults/main.yml. - name: create CI image build directory become: true become_user: "{{ gitea_runner_user }}" ansible.builtin.file: path: "{{ gitea_runner_home }}/ci-images" state: directory mode: "0755" tags: gitea-actions - name: create gitea-runner registry auth directory become: true become_user: "{{ gitea_runner_user }}" ansible.builtin.file: path: "{{ gitea_ci_registry_authfile | dirname }}" state: directory mode: "0700" tags: gitea-actions - name: log gitea-runner in to the Gitea container registry become: true become_user: "{{ gitea_runner_user }}" containers.podman.podman_login: registry: "{{ gitea_ci_registry }}" username: "{{ gitea_registry_username }}" password: "{{ gitea_registry_token }}" authfile: "{{ gitea_ci_registry_authfile }}" environment: XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}" no_log: true tags: gitea-actions - name: stage CI Containerfiles become: true become_user: "{{ gitea_runner_user }}" ansible.builtin.template: src: "{{ item.template }}" dest: "{{ gitea_runner_home }}/ci-images/{{ item.containerfile }}" mode: "0644" loop: "{{ gitea_ci_images }}" loop_control: label: "{{ item.containerfile }}" register: ci_containerfiles tags: gitea-actions # A missing image here is normal (first push, or a new tag): the build below # creates it. Anything already present locally is left untouched. - name: restore CI images from the registry become: true become_user: "{{ gitea_runner_user }}" containers.podman.podman_image: name: "{{ item.image }}" auth_file: "{{ gitea_ci_registry_authfile }}" environment: XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}" loop: "{{ gitea_ci_images }}" loop_control: label: "{{ item.image }}" when: not (ci_containerfiles.results | selectattr('item.image', 'equalto', item.image) | first).changed failed_when: false tags: gitea-actions - name: build and push CI images become: true become_user: "{{ gitea_runner_user }}" containers.podman.podman_image: name: "{{ item.image }}" path: "{{ gitea_runner_home }}/ci-images" build: file: "{{ gitea_runner_home }}/ci-images/{{ item.containerfile }}" # Exempts the image from the nightly CI prune (gitea_ci_keep_label). extra_args: "--label {{ gitea_ci_keep_label }}=true" force: "{{ (ci_containerfiles.results | selectattr('item.image', 'equalto', item.image) | first).changed }}" push: true auth_file: "{{ gitea_ci_registry_authfile }}" environment: XDG_RUNTIME_DIR: "/run/user/{{ gitea_runner_uid }}" loop: "{{ gitea_ci_images }}" loop_control: label: "{{ item.image }}" tags: gitea-actions