From 5f9ab68bd97aa30d97302c042caf43ff95d86f10 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rub=C3=A9n=20De=20la=20Torre=20Vico?= Date: Mon, 13 Oct 2025 10:31:02 +0200 Subject: [PATCH] feat(mcp): add GitHub Action to publish MCP Server container to DockerHub (#8875) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com> --- .../mcp-server-build-push-containers.yml | 90 +++++++++++++++++++ 1 file changed, 90 insertions(+) create mode 100644 .github/workflows/mcp-server-build-push-containers.yml diff --git a/.github/workflows/mcp-server-build-push-containers.yml b/.github/workflows/mcp-server-build-push-containers.yml new file mode 100644 index 0000000000..ec10caddab --- /dev/null +++ b/.github/workflows/mcp-server-build-push-containers.yml @@ -0,0 +1,90 @@ +name: MCP Server - Build and Push containers + +on: + push: + branches: + - "master" + paths: + - "mcp_server/**" + - ".github/workflows/mcp-server-build-push-containers.yml" + + # Uncomment the below code to test this action on PRs + # pull_request: + # branches: + # - "master" + # paths: + # - "mcp_server/**" + # - ".github/workflows/mcp-server-build-push-containers.yml" + + release: + types: [published] + +env: + # Tags + LATEST_TAG: latest + + WORKING_DIRECTORY: ./mcp_server + + # Container Registries + PROWLERCLOUD_DOCKERHUB_REPOSITORY: prowlercloud + PROWLERCLOUD_DOCKERHUB_IMAGE: prowler-mcp + +jobs: + repository-check: + name: Repository check + runs-on: ubuntu-latest + outputs: + is_repo: ${{ steps.repository_check.outputs.is_repo }} + steps: + - name: Repository check + id: repository_check + working-directory: /tmp + run: | + if [[ ${{ github.repository }} == "prowler-cloud/prowler" ]] + then + echo "is_repo=true" >> "${GITHUB_OUTPUT}" + else + echo "This action only runs for prowler-cloud/prowler" + echo "is_repo=false" >> "${GITHUB_OUTPUT}" + fi + + container-build-push: + needs: repository-check + if: needs.repository-check.outputs.is_repo == 'true' + runs-on: ubuntu-latest + defaults: + run: + working-directory: ${{ env.WORKING_DIRECTORY }} + + steps: + - name: Checkout + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 + + - name: Set short git commit SHA + id: vars + run: | + shortSha=$(git rev-parse --short ${{ github.sha }}) + echo "SHORT_SHA=${shortSha}" >> $GITHUB_ENV + + - name: Login to DockerHub + uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 + + - name: Build and push container image (latest) + # Comment the following line for testing + if: github.event_name == 'push' + uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 + with: + context: ${{ env.WORKING_DIRECTORY }} + # Set push: false for testing + push: true + tags: | + ${{ env.PROWLERCLOUD_DOCKERHUB_REPOSITORY }}/${{ env.PROWLERCLOUD_DOCKERHUB_IMAGE }}:${{ env.LATEST_TAG }} + ${{ env.PROWLERCLOUD_DOCKERHUB_REPOSITORY }}/${{ env.PROWLERCLOUD_DOCKERHUB_IMAGE }}:${{ env.SHORT_SHA }} + cache-from: type=gha + cache-to: type=gha,mode=max