name: Docker Publish on: workflow_run: workflows: ['Quality Gate'] branches: [main] types: [completed] push: tags: - 'v*.*.*' workflow_dispatch: concurrency: group: docker-publish-${{ github.ref }} cancel-in-progress: false permissions: contents: read packages: write id-token: write env: GHCR_IMAGE: ghcr.io/${{ github.repository }} DOCKERHUB_IMAGE: docker.io/builderz-labs/mission-control DOCKERHUB_ENABLED: ${{ secrets.DOCKERHUB_USERNAME != '' && secrets.DOCKERHUB_TOKEN != '' }} jobs: publish: if: > github.event_name == 'workflow_dispatch' || github.event_name == 'push' || ( github.event_name == 'workflow_run' && github.event.workflow_run.conclusion == 'success' ) runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 with: ref: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_sha || github.sha }} - name: Set up QEMU uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to GHCR uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Log in to Docker Hub if: env.DOCKERHUB_ENABLED == 'true' uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Docker metadata id: meta uses: docker/metadata-action@v5 with: images: | ${{ env.GHCR_IMAGE }} name=${{ env.DOCKERHUB_IMAGE }},enable=${{ env.DOCKERHUB_ENABLED }} tags: | type=sha,prefix=sha- type=ref,event=branch type=ref,event=tag type=semver,pattern={{version}} type=semver,pattern={{major}}.{{minor}} type=raw,value=latest,enable={{is_default_branch}} - name: Build and push image uses: docker/build-push-action@v6 with: context: . file: ./Dockerfile push: true platforms: linux/amd64,linux/arm64 tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max provenance: true sbom: true