diff --git a/.dockerignore b/.dockerignore index 5ed6417..2a34dc5 100644 --- a/.dockerignore +++ b/.dockerignore @@ -8,4 +8,7 @@ .vscode Dockerfile README.md -build \ No newline at end of file +build +# CI build leftovers at the repo root (the NDK alone is several GB) +android-ndk-r23b +*.zip diff --git a/.github/workflows/build-for-x86_64.yml b/.github/workflows/build-for-x86_64.yml index 67dd2a8..61292de 100644 --- a/.github/workflows/build-for-x86_64.yml +++ b/.github/workflows/build-for-x86_64.yml @@ -5,9 +5,14 @@ on: branches: [ "main" ] pull_request: branches: [ "main" ] + workflow_dispatch: permissions: contents: write + packages: write + +env: + REGISTRY: ghcr.io jobs: build: @@ -56,4 +61,45 @@ jobs: name: Wrapper.x86_64.latest tag_name: wrapper.x86_64.latest make_latest: true - overwrite: true \ No newline at end of file + overwrite: true + + # Both ExternalProject targets compile to ./wrapper, so a plain `make` leaves + # whichever ran last. Re-make the privileged one explicitly: the image is + # documented to run --privileged. Runs after the zip so the release is unchanged. + - name: Rebuild privileged wrapper for the image + run: cmake --build build --target wrapper_exe + + - name: Compute image name + id: image + run: echo "name=${REGISTRY}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_OUTPUT" + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log in to GitHub Container Registry + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract image metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ steps.image.outputs.name }} + tags: | + type=ref,event=branch + type=ref,event=pr + type=sha,format=long + type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }} + + - name: Build and push Docker image (linux/amd64) + uses: docker/build-push-action@v6 + with: + context: . + platforms: linux/amd64 + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }}