Files
bsky-social-app/.github/workflows/build-and-push-ogcard-aws.yaml
T
Austin McKinley 3213eeb273 ci: build ogcard image on push to main
The workflow only triggered on pull_request, which meant the image
tagged with a PR commit SHA would get pushed to ECR, but the merge
commit to main never produced a fresh image. Deploy tooling resolving
main to an ECR tag would either miss or pick up a stale PR build.

Match bskyweb-aws: `push: branches: [main]` + `workflow_dispatch`.
Drops the pull_request trigger entirely. If Dockerfile validation on
PRs is wanted back, we can add a hybrid pattern later (build-on-PR,
push-only-on-main).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 12:38:29 -07:00

57 lines
1.5 KiB
YAML

name: build-and-push-ogcard-aws
on:
workflow_dispatch:
push:
branches:
- main
env:
REGISTRY: ${{ secrets.AWS_ECR_REGISTRY_USEAST2_PACKAGES_REGISTRY }}
USERNAME: ${{ secrets.AWS_ECR_REGISTRY_USEAST2_PACKAGES_USERNAME }}
PASSWORD: ${{ secrets.AWS_ECR_REGISTRY_USEAST2_PACKAGES_PASSWORD }}
IMAGE_NAME: bskyogcard
jobs:
ogcard-container-aws:
if: github.repository == 'bluesky-social/social-app'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Setup Docker buildx
uses: docker/setup-buildx-action@v1
- name: Log into registry ${{ env.REGISTRY }}
uses: docker/login-action@v2
with:
registry: ${{ env.REGISTRY }}
username: ${{ env.USERNAME}}
password: ${{ env.PASSWORD }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v4
with:
images: |
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=sha,enable=true,priority=100,prefix=,suffix=,format=long
- name: Build and push Docker image
id: build-and-push
uses: docker/build-push-action@v4
with:
context: .
push: true
file: ./Dockerfile.bskyogcard
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max