Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 12 additions & 3 deletions content/manuals/build-cloud/ci.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,18 +94,20 @@ If you are not an organization administrator:

### GitHub Actions

<!-- TODO: Confirm whether standard Buildx requires a minimum setup-buildx-action version. -->

```yaml
name: ci

on:
push:
branches:
- "main"
pull_request:
branches:
- "main"

jobs:
docker:
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
steps:
- name: Login to Docker Hub
Expand All @@ -129,6 +131,9 @@ jobs:
outputs: ${{ github.event_name == 'pull_request' && 'type=cacheonly' || 'type=registry' }}
```

Pull requests from forks skip this job because they don't have access to the
required secrets.

The example above uses `docker/build-push-action`, which automatically uses the
builder set up by `setup-buildx-action`. If you need to use the `docker build`
command directly instead, you have two options:
Expand Down Expand Up @@ -174,6 +179,8 @@ variables:
# Build multi-platform image and push to a registry
build_push:
stage: build
rules:
- if: '$CI_PIPELINE_SOURCE == "push" && $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH'
script:
- |
docker buildx build \
Expand All @@ -184,6 +191,8 @@ build_push:
# Build an image and discard the result
build_cache:
stage: build
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event" && $CI_MERGE_REQUEST_SOURCE_PROJECT_PATH == $CI_PROJECT_PATH'
script:
- |
docker buildx build \
Expand Down Expand Up @@ -271,7 +280,7 @@ steps:
key: build-push
plugins:
- docker-login#v2.1.0:
username: DOCKER_ACCOUNT
username: "<DOCKER_ACCOUNT>" # replace with your organization name or username
password-env: DOCKER_ACCESS_TOKEN # the variable name in the environment hook
```

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -202,8 +202,6 @@ RUN apt-get update

## Provenance attestation example

<!-- TODO: add a link to the definitions page, imported from moby/buildkit -->

The following example shows what a JSON representation of a provenance
attestation with `mode=max` looks like:

Expand Down