From ea27817a2ccf953851817ad90f3b98d2f817ed50 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 29 Oct 2025 11:59:39 +0100 Subject: [PATCH] chore(github): improve API container build and push action (#9032) --- ...iners.yml => api-container-build-push.yml} | 86 ++++++++----------- 1 file changed, 34 insertions(+), 52 deletions(-) rename .github/workflows/{api-build-lint-push-containers.yml => api-container-build-push.yml} (56%) diff --git a/.github/workflows/api-build-lint-push-containers.yml b/.github/workflows/api-container-build-push.yml similarity index 56% rename from .github/workflows/api-build-lint-push-containers.yml rename to .github/workflows/api-container-build-push.yml index e7010cef24..db0a30f027 100644 --- a/.github/workflows/api-build-lint-push-containers.yml +++ b/.github/workflows/api-container-build-push.yml @@ -1,75 +1,59 @@ -name: API - Build and Push containers +name: 'API: Container Build and Push' on: push: branches: - - "master" + - 'master' paths: - - "api/**" - - "prowler/**" - - ".github/workflows/api-build-lint-push-containers.yml" - - # Uncomment the code below to test this action on PRs - # pull_request: - # branches: - # - "master" - # paths: - # - "api/**" - # - ".github/workflows/api-build-lint-push-containers.yml" - + - 'api/**' + - 'prowler/**' + - '.github/workflows/api-build-lint-push-containers.yml' release: - types: [published] + types: + - 'published' + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true env: # Tags LATEST_TAG: latest RELEASE_TAG: ${{ github.event.release.tag_name }} STABLE_TAG: stable - WORKING_DIRECTORY: ./api - # Container Registries + # Container registries PROWLERCLOUD_DOCKERHUB_REPOSITORY: prowlercloud PROWLERCLOUD_DOCKERHUB_IMAGE: prowler-api jobs: - repository-check: - name: Repository check + setup: + if: github.repository == 'prowler-cloud/prowler' runs-on: ubuntu-latest + timeout-minutes: 5 outputs: - is_repo: ${{ steps.repository_check.outputs.is_repo }} + short-sha: ${{ steps.set-short-sha.outputs.short-sha }} steps: - - name: Repository check - id: repository_check - working-directory: /tmp - run: | - if [[ ${{ github.repository }} == "prowler-cloud/prowler" ]] - then - echo "is_repo=true" >> "${GITHUB_OUTPUT}" - else - echo "This action only runs for prowler-cloud/prowler" - echo "is_repo=false" >> "${GITHUB_OUTPUT}" - fi + - name: Calculate short SHA + id: set-short-sha + run: echo "short-sha=${GITHUB_SHA::7}" >> $GITHUB_OUTPUT - # Build Prowler OSS container container-build-push: - needs: repository-check - if: needs.repository-check.outputs.is_repo == 'true' + needs: setup runs-on: ubuntu-latest - defaults: - run: - working-directory: ${{ env.WORKING_DIRECTORY }} + timeout-minutes: 30 + permissions: + contents: read + packages: write steps: - - name: Checkout + - name: Checkout repository uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - - name: Set short git commit SHA - id: vars - run: | - shortSha=$(git rev-parse --short ${{ github.sha }}) - echo "SHORT_SHA=${shortSha}" >> $GITHUB_ENV - - name: Login to DockerHub uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 with: @@ -79,21 +63,19 @@ jobs: - name: Set up Docker Buildx uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 - - name: Build and push container image (latest) - # Comment the following line for testing + - name: Build and push API container (latest) if: github.event_name == 'push' uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 with: context: ${{ env.WORKING_DIRECTORY }} - # Set push: false for testing push: true tags: | ${{ env.PROWLERCLOUD_DOCKERHUB_REPOSITORY }}/${{ env.PROWLERCLOUD_DOCKERHUB_IMAGE }}:${{ env.LATEST_TAG }} - ${{ env.PROWLERCLOUD_DOCKERHUB_REPOSITORY }}/${{ env.PROWLERCLOUD_DOCKERHUB_IMAGE }}:${{ env.SHORT_SHA }} + ${{ env.PROWLERCLOUD_DOCKERHUB_REPOSITORY }}/${{ env.PROWLERCLOUD_DOCKERHUB_IMAGE }}:${{ needs.setup.outputs.short-sha }} cache-from: type=gha cache-to: type=gha,mode=max - - name: Build and push container image (release) + - name: Build and push API container (release) if: github.event_name == 'release' uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 with: @@ -105,11 +87,11 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - - name: Trigger deployment + - name: Trigger API deployment if: github.event_name == 'push' uses: peter-evans/repository-dispatch@5fc4efd1a4797ddb68ffd0714a238564e4cc0e6f # v4.0.0 with: token: ${{ secrets.PROWLER_BOT_ACCESS_TOKEN }} repository: ${{ secrets.CLOUD_DISPATCH }} - event-type: prowler-api-deploy - client-payload: '{"sha": "${{ github.sha }}", "short_sha": "${{ env.SHORT_SHA }}"}' + event-type: prowler-api-deployment + client-payload: '{"sha": "${{ github.sha }}", "short_sha": "${{ needs.setup.outputs.short-sha }}"}'