name: Build and push server image on: push: branches: [main] paths: - "server/**" - ".gitea/workflows/server-docker-build.yml" jobs: build-and-push: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: # 10.0.0.246:3000 is plain HTTP (a bare LAN IP:port, no TLS cert # would validate for it), but BuildKit defaults to HTTPS for any # registry that isn't docker.io. This tells BuildKit specifically # to skip that for this one host. NOTE: this only covers the # actual build+push (BuildKit). The "Log in" step below runs a # plain `docker login`, which goes through the classic Docker # CLI/daemon instead of BuildKit and does NOT read this config -- # that one only works once the Docker daemon backing this runner # has 10.0.0.246:3000 listed under "insecure-registries" in its # own /etc/docker/daemon.json (then `systemctl restart docker`). # That's runner-host infrastructure this repo can't configure. config-inline: | [registry."10.0.0.246:3000"] http = true insecure = true - name: Log in to local Gitea Container Registry uses: docker/login-action@v3 with: # Pushed here instead of git.thumeit.com (still the source repo, # just not the image registry anymore) -- since whiteboard mode # added Node + native resvg bindings, the image grew past # Cloudflare's payload-size limit in front of that host and # every push 413'd. This LAN address has nothing in front of it. registry: 10.0.0.246:3000 username: tfaour password: ${{ secrets.REGISTRY_TOKEN }} - name: Build and push uses: docker/build-push-action@v6 with: context: ./server push: true tags: | 10.0.0.246:3000/tfaour/espresso-frame-server:latest 10.0.0.246:3000/tfaour/espresso-frame-server:${{ gitea.sha }}