Build and Push Docker Images on Tag #7
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and Push Docker Images on Tag | |
| on: | |
| push: | |
| tags: | |
| - "*" | |
| workflow_dispatch: | |
| env: | |
| IS_DRY_RUN: ${{ github.event_name == 'workflow_dispatch' }} | |
| EDGE_TAG: ${{ startsWith(github.ref_name, 'nightly-latest') }} | |
| jobs: | |
| # Determine which components to build based on the tag | |
| determine-builds: | |
| # NOTE: Github-hosted runners have about 20s faster queue times and are preferred here. | |
| runs-on: ubuntu-slim | |
| outputs: | |
| build-web: ${{ steps.check.outputs.build-web }} | |
| build-web-cloud: ${{ steps.check.outputs.build-web-cloud }} | |
| build-backend: ${{ steps.check.outputs.build-backend }} | |
| build-model-server: ${{ steps.check.outputs.build-model-server }} | |
| is-cloud-tag: ${{ steps.check.outputs.is-cloud-tag }} | |
| is-stable: ${{ steps.check.outputs.is-stable }} | |
| is-beta: ${{ steps.check.outputs.is-beta }} | |
| is-stable-standalone: ${{ steps.check.outputs.is-stable-standalone }} | |
| is-beta-standalone: ${{ steps.check.outputs.is-beta-standalone }} | |
| steps: | |
| - name: Check which components to build and version info | |
| id: check | |
| run: | | |
| TAG="${{ github.ref_name }}" | |
| IS_CLOUD=false | |
| BUILD_WEB=false | |
| BUILD_WEB_CLOUD=false | |
| BUILD_BACKEND=true | |
| BUILD_MODEL_SERVER=true | |
| IS_STABLE=false | |
| IS_BETA=false | |
| IS_STABLE_STANDALONE=false | |
| IS_BETA_STANDALONE=false | |
| if [[ "$TAG" == *cloud* ]]; then | |
| IS_CLOUD=true | |
| BUILD_WEB_CLOUD=true | |
| else | |
| BUILD_WEB=true | |
| fi | |
| # Version checks (for web - any stable version) | |
| if [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then | |
| IS_STABLE=true | |
| fi | |
| if [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+-beta\.[0-9]+$ ]]; then | |
| IS_BETA=true | |
| fi | |
| # Version checks (for backend/model-server - stable version excluding cloud tags) | |
| if [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]] && [[ "$TAG" != *cloud* ]]; then | |
| IS_STABLE_STANDALONE=true | |
| fi | |
| if [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+-beta\.[0-9]+$ ]] && [[ "$TAG" != *cloud* ]]; then | |
| IS_BETA_STANDALONE=true | |
| fi | |
| { | |
| echo "build-web=$BUILD_WEB" | |
| echo "build-web-cloud=$BUILD_WEB_CLOUD" | |
| echo "build-backend=$BUILD_BACKEND" | |
| echo "build-model-server=$BUILD_MODEL_SERVER" | |
| echo "is-cloud-tag=$IS_CLOUD" | |
| echo "is-stable=$IS_STABLE" | |
| echo "is-beta=$IS_BETA" | |
| echo "is-stable-standalone=$IS_STABLE_STANDALONE" | |
| echo "is-beta-standalone=$IS_BETA_STANDALONE" | |
| } >> "$GITHUB_OUTPUT" | |
| build-web: | |
| needs: determine-builds | |
| if: needs.determine-builds.outputs.build-web == 'true' | |
| runs-on: | |
| - runs-on | |
| - runner=4cpu-linux-arm64 | |
| - run-id=${{ github.run_id }}-web-build | |
| - extras=ecr-cache | |
| env: | |
| REGISTRY_IMAGE: onyxdotapp/onyx-web-server | |
| DEPLOYMENT: standalone | |
| steps: | |
| - uses: runs-on/action@cd2b598b0515d39d78c38a02d529db87d2196d1e # ratchet:runs-on/action@v2 | |
| with: | |
| metrics: disk | |
| - name: Checkout | |
| uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # ratchet:actions/checkout@v4 | |
| - name: Docker meta | |
| id: meta | |
| uses: docker/metadata-action@318604b99e75e41977312d83839a89be02ca4893 # ratchet:docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY_IMAGE }} | |
| flavor: | | |
| latest=false | |
| tags: | | |
| type=raw,value=${{ github.ref_name }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-stable == 'true' && 'latest' || '' }} | |
| type=raw,value=${{ env.EDGE_TAG == 'true' && 'edge' || '' }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-beta == 'true' && 'beta' || '' }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # ratchet:docker/setup-buildx-action@v3 | |
| - name: Login to Docker Hub | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # ratchet:docker/login-action@v3 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # ratchet:docker/build-push-action@v6 | |
| with: | |
| context: ./web | |
| file: ./web/Dockerfile | |
| platforms: linux/amd64,linux/arm64 | |
| push: ${{ env.IS_DRY_RUN != 'true' }} | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: | | |
| ONYX_VERSION=${{ github.ref_name }} | |
| NODE_OPTIONS=--max-old-space-size=8192 | |
| cache-from: | | |
| type=registry,ref=${{ env.REGISTRY_IMAGE }}:latest | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:web-${{ env.DEPLOYMENT }}-cache | |
| cache-to: | | |
| type=inline | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:web-${{ env.DEPLOYMENT }}-cache,mode=max | |
| - name: Run Trivy vulnerability scanner | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # ratchet:nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 30 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: | | |
| docker run --rm -v $HOME/.cache/trivy:/root/.cache/trivy \ | |
| -e TRIVY_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-db:2" \ | |
| -e TRIVY_JAVA_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-java-db:1" \ | |
| -e TRIVY_USERNAME="${{ secrets.DOCKER_USERNAME }}" \ | |
| -e TRIVY_PASSWORD="${{ secrets.DOCKER_TOKEN }}" \ | |
| aquasec/trivy@sha256:a22415a38938a56c379387a8163fcb0ce38b10ace73e593475d3658d578b2436 \ | |
| image \ | |
| --skip-version-check \ | |
| --timeout 20m \ | |
| --severity CRITICAL,HIGH \ | |
| docker.io/${{ env.REGISTRY_IMAGE }}:${{ github.ref_name }} | |
| build-web-cloud: | |
| needs: determine-builds | |
| if: needs.determine-builds.outputs.build-web-cloud == 'true' | |
| runs-on: | |
| - runs-on | |
| - runner=4cpu-linux-arm64 | |
| - run-id=${{ github.run_id }}-web-cloud-build | |
| - extras=ecr-cache | |
| env: | |
| REGISTRY_IMAGE: onyxdotapp/onyx-web-server-cloud | |
| DEPLOYMENT: cloud | |
| steps: | |
| - uses: runs-on/action@cd2b598b0515d39d78c38a02d529db87d2196d1e # ratchet:runs-on/action@v2 | |
| with: | |
| metrics: disk | |
| - name: Checkout | |
| uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # ratchet:actions/checkout@v4 | |
| - name: Docker meta | |
| id: meta | |
| uses: docker/metadata-action@318604b99e75e41977312d83839a89be02ca4893 # ratchet:docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY_IMAGE }} | |
| flavor: | | |
| latest=false | |
| tags: | | |
| type=raw,value=${{ github.ref_name }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # ratchet:docker/setup-buildx-action@v3 | |
| - name: Login to Docker Hub | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # ratchet:docker/login-action@v3 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # ratchet:docker/build-push-action@v6 | |
| with: | |
| context: ./web | |
| file: ./web/Dockerfile | |
| platforms: linux/amd64,linux/arm64 | |
| push: ${{ env.IS_DRY_RUN != 'true' }} | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: | | |
| ONYX_VERSION=${{ github.ref_name }} | |
| NEXT_PUBLIC_CLOUD_ENABLED=true | |
| NEXT_PUBLIC_POSTHOG_KEY=${{ secrets.POSTHOG_KEY }} | |
| NEXT_PUBLIC_POSTHOG_HOST=${{ secrets.POSTHOG_HOST }} | |
| NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN }} | |
| NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY=${{ secrets.STRIPE_PUBLISHABLE_KEY }} | |
| NEXT_PUBLIC_GTM_ENABLED=true | |
| NEXT_PUBLIC_FORGOT_PASSWORD_ENABLED=true | |
| NEXT_PUBLIC_INCLUDE_ERROR_POPUP_SUPPORT_LINK=true | |
| NODE_OPTIONS=--max-old-space-size=8192 | |
| cache-from: | | |
| type=registry,ref=${{ env.REGISTRY_IMAGE }}:latest | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:cloudweb-${{ env.DEPLOYMENT }}-cache | |
| cache-to: | | |
| type=inline | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:cloudweb-${{ env.DEPLOYMENT }}-cache,mode=max | |
| - name: Run Trivy vulnerability scanner | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # ratchet:nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 30 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: | | |
| docker run --rm -v $HOME/.cache/trivy:/root/.cache/trivy \ | |
| -e TRIVY_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-db:2" \ | |
| -e TRIVY_JAVA_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-java-db:1" \ | |
| -e TRIVY_USERNAME="${{ secrets.DOCKER_USERNAME }}" \ | |
| -e TRIVY_PASSWORD="${{ secrets.DOCKER_TOKEN }}" \ | |
| aquasec/trivy@sha256:a22415a38938a56c379387a8163fcb0ce38b10ace73e593475d3658d578b2436 \ | |
| image \ | |
| --skip-version-check \ | |
| --timeout 20m \ | |
| --severity CRITICAL,HIGH \ | |
| docker.io/${{ env.REGISTRY_IMAGE }}:${{ github.ref_name }} | |
| build-backend: | |
| needs: determine-builds | |
| if: needs.determine-builds.outputs.build-backend == 'true' | |
| runs-on: | |
| - runs-on | |
| - runner=2cpu-linux-arm64 | |
| - run-id=${{ github.run_id }}-backend-build | |
| - extras=ecr-cache | |
| env: | |
| REGISTRY_IMAGE: ${{ contains(github.ref_name, 'cloud') && 'onyxdotapp/onyx-backend-cloud' || 'onyxdotapp/onyx-backend' }} | |
| DEPLOYMENT: ${{ contains(github.ref_name, 'cloud') && 'cloud' || 'standalone' }} | |
| steps: | |
| - uses: runs-on/action@cd2b598b0515d39d78c38a02d529db87d2196d1e # ratchet:runs-on/action@v2 | |
| with: | |
| metrics: disk | |
| - name: Checkout code | |
| uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # ratchet:actions/checkout@v4 | |
| - name: Docker meta | |
| id: meta | |
| uses: docker/metadata-action@318604b99e75e41977312d83839a89be02ca4893 # ratchet:docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY_IMAGE }} | |
| flavor: | | |
| latest=false | |
| tags: | | |
| type=raw,value=${{ github.ref_name }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-stable-standalone == 'true' && 'latest' || '' }} | |
| type=raw,value=${{ env.EDGE_TAG == 'true' && 'edge' || '' }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-beta-standalone == 'true' && 'beta' || '' }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # ratchet:docker/setup-buildx-action@v3 | |
| - name: Login to Docker Hub | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # ratchet:docker/login-action@v3 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # ratchet:docker/build-push-action@v6 | |
| with: | |
| context: ./backend | |
| file: ./backend/Dockerfile | |
| platforms: linux/amd64,linux/arm64 | |
| push: ${{ env.IS_DRY_RUN != 'true' }} | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: | | |
| ONYX_VERSION=${{ github.ref_name }} | |
| cache-from: | | |
| type=registry,ref=${{ env.REGISTRY_IMAGE }}:latest | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:backend-${{ env.DEPLOYMENT }}-cache | |
| cache-to: | | |
| type=inline | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:backend-${{ env.DEPLOYMENT }}-cache,mode=max | |
| - name: Run Trivy vulnerability scanner | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # ratchet:nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 30 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: | | |
| REGISTRY_IMAGE="${{ env.REGISTRY_IMAGE }}" | |
| docker run --rm -v $HOME/.cache/trivy:/root/.cache/trivy \ | |
| -v ${{ github.workspace }}/backend/.trivyignore:/tmp/.trivyignore:ro \ | |
| -e TRIVY_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-db:2" \ | |
| -e TRIVY_JAVA_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-java-db:1" \ | |
| -e TRIVY_USERNAME="${{ secrets.DOCKER_USERNAME }}" \ | |
| -e TRIVY_PASSWORD="${{ secrets.DOCKER_TOKEN }}" \ | |
| aquasec/trivy@sha256:a22415a38938a56c379387a8163fcb0ce38b10ace73e593475d3658d578b2436 \ | |
| image \ | |
| --skip-version-check \ | |
| --timeout 20m \ | |
| --severity CRITICAL,HIGH \ | |
| --ignorefile /tmp/.trivyignore \ | |
| docker.io/${REGISTRY_IMAGE}:${{ github.ref_name }} | |
| build-model-server: | |
| needs: determine-builds | |
| if: needs.determine-builds.outputs.build-model-server == 'true' | |
| runs-on: | |
| - runs-on | |
| - runner=2cpu-linux-arm64 | |
| - run-id=${{ github.run_id }}-model-server-build | |
| - extras=ecr-cache | |
| env: | |
| REGISTRY_IMAGE: ${{ contains(github.ref_name, 'cloud') && 'onyxdotapp/onyx-model-server-cloud' || 'onyxdotapp/onyx-model-server' }} | |
| DOCKER_BUILDKIT: 1 | |
| BUILDKIT_PROGRESS: plain | |
| DEPLOYMENT: ${{ contains(github.ref_name, 'cloud') && 'cloud' || 'standalone' }} | |
| steps: | |
| - uses: runs-on/action@cd2b598b0515d39d78c38a02d529db87d2196d1e # ratchet:runs-on/action@v2 | |
| with: | |
| metrics: disk | |
| - name: Checkout code | |
| uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # ratchet:actions/checkout@v4 | |
| - name: Docker meta | |
| id: meta | |
| uses: docker/metadata-action@318604b99e75e41977312d83839a89be02ca4893 # ratchet:docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY_IMAGE }} | |
| flavor: | | |
| latest=false | |
| tags: | | |
| type=raw,value=${{ github.ref_name }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-stable-standalone == 'true' && 'latest' || '' }} | |
| type=raw,value=${{ env.EDGE_TAG == 'true' && 'edge' || '' }} | |
| type=raw,value=${{ needs.determine-builds.outputs.is-beta-standalone == 'true' && 'beta' || '' }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # ratchet:docker/setup-buildx-action@v3 | |
| with: | |
| driver-opts: | | |
| image=moby/buildkit:latest | |
| network=host | |
| - name: Login to Docker Hub | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # ratchet:docker/login-action@v3 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # ratchet:docker/build-push-action@v6 | |
| with: | |
| context: ./backend | |
| file: ./backend/Dockerfile.model_server | |
| platforms: linux/amd64,linux/arm64 | |
| push: ${{ env.IS_DRY_RUN != 'true' }} | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| build-args: | | |
| ONYX_VERSION=${{ github.ref_name }} | |
| cache-from: | | |
| type=registry,ref=${{ env.REGISTRY_IMAGE }}:latest | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:model-server-${{ env.DEPLOYMENT }}-cache | |
| cache-to: | | |
| type=inline | |
| type=registry,ref=${{ env.RUNS_ON_ECR_CACHE }}:model-server-${{ env.DEPLOYMENT }}-cache,mode=max | |
| - name: Run Trivy vulnerability scanner | |
| if: env.IS_DRY_RUN != 'true' | |
| uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # ratchet:nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 30 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: | | |
| REGISTRY_IMAGE="${{ env.REGISTRY_IMAGE }}" | |
| docker run --rm -v $HOME/.cache/trivy:/root/.cache/trivy \ | |
| -e TRIVY_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-db:2" \ | |
| -e TRIVY_JAVA_DB_REPOSITORY="public.ecr.aws/aquasecurity/trivy-java-db:1" \ | |
| -e TRIVY_USERNAME="${{ secrets.DOCKER_USERNAME }}" \ | |
| -e TRIVY_PASSWORD="${{ secrets.DOCKER_TOKEN }}" \ | |
| aquasec/trivy@sha256:a22415a38938a56c379387a8163fcb0ce38b10ace73e593475d3658d578b2436 \ | |
| image \ | |
| --skip-version-check \ | |
| --timeout 20m \ | |
| --severity CRITICAL,HIGH \ | |
| docker.io/${REGISTRY_IMAGE}:${{ github.ref_name }} |