name: Daily Update Pipeline on: schedule: # Runs every day at 3:00 AM UTC - cron: '0 3 * * *' workflow_dispatch: # Allows manual triggering jobs: check-images: runs-on: ubuntu-latest outputs: base_image_digest: ${{ steps.mlflow-base.outputs.base_image_digest }} should_build: ${{ steps.decision.outputs.should_build }} steps: - name: Log in to Gitea Container Registry run: | mkdir -p ~/.docker echo '{"insecure-registries": ["10.0.0.2:3000"]}' > ~/.docker/config.json echo "${{ secrets.CI_RUNNER_TOKEN }}" | docker login 10.0.0.2:3000 --username "${{ gitea.actor }}" --password-stdin - name: Check MLflow-full image id: mlflow-full run: | MANIFEST=$(docker manifest inspect "gitea.gt-proj.com/brian/mlflow-full:latest" 2>/dev/null || echo "{}") if [ "$MANIFEST" != "{}" ]; then DIGEST=$(echo "$MANIFEST" | jq -r '.manifests[]? | select(.platform.architecture == "amd64" and .platform.os == "linux") | .digest // empty') echo "digest=$DIGEST" >> $GITHUB_OUTPUT echo "manifest_found=true" >> $GITHUB_OUTPUT echo "Manifest found for MLflow-full image with digest: $DIGEST" else echo "manifest_found=false" >> $GITHUB_OUTPUT echo "MLflow-full image not found" fi - name: Check MLflow base image id: mlflow-base if: steps.mlflow-full.outputs.manifest_found == 'true' run: | MANIFEST=$(docker manifest inspect ghcr.io/mlflow/mlflow:latest 2>/dev/null || echo "{}") if [ "$MANIFEST" != "{}" ]; then DIGEST=$(echo "$MANIFEST" | jq -r '.manifests[]? | select(.platform.architecture == "amd64" and .platform.os == "linux") | .digest // empty') echo "digest=$DIGEST" >> $GITHUB_OUTPUT echo "manifest_found=true" >> $GITHUB_OUTPUT echo "Manifest found for MLflow base image with digest: $DIGEST" else echo "manifest_found=false" >> $GITHUB_OUTPUT echo "MLflow base image not found" fi - name: Build decision id: decision run: | if [ "${{ steps.mlflow-base.outputs.manifest_found }}" == "true" ] && \ [ "${{ steps.mlflow-full.outputs.manifest_found }}" == "true" ]; then echo "✅ Both MLflow base and MLflow-full images found" echo "should_build=true" >> $GITHUB_OUTPUT elif [ "${{ steps.mlflow-base.outputs.manifest_found }}" != "true" ]; then echo "❌ MLflow base image not found" echo "should_build=false" >> $GITHUB_OUTPUT else echo "❌ MLflow-full image not found" echo "should_build=false" >> $GITHUB_OUTPUT fi build-and-publish: needs: check-images if: needs.check-images.outputs.should_build == 'true' runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: config-inline: | [registry."10.0.0.2:3000"] http = true insecure = true - name: Log in to Gitea Container Registry run: | # Configure Docker to allow insecure registry for this session mkdir -p ~/.docker echo '{ "auths": {}, "insecure-registries": ["10.0.0.2:3000"] }' > ~/.docker/config.json # Login using direct docker command echo "${{ secrets.CI_RUNNER_TOKEN }}" | docker login 10.0.0.2:3000 --username "${{ gitea.actor }}" --password-stdin - name: Extract metadata id: meta uses: docker/metadata-action@v5 with: images: 10.0.0.2:3000/${{ gitea.repository_owner }}/${{ gitea.event.repository.name }} tags: | type=schedule,pattern={{date 'YYYYMMDD'}} type=raw,value=latest labels: | base-image.digest=${{ needs.check-images.outputs.base_image_digest }} - name: Build and push Docker image id: build-publish uses: docker/build-push-action@v5 with: context: . push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max build-args: | BASE_IMAGE_DIGEST=${{ needs.check-images.outputs.base_image_digest }} - name: Update deployment info run: | echo "Docker image built and pushed successfully at $(date)" echo "Image tags:" echo "${{ steps.meta.outputs.tags }}"