Refactor ci2 #8
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: concrete-compiler publish docker images | |
on: | |
workflow_dispatch: | |
pull_request: | |
push: | |
paths: | |
- .github/workflows/concrete_compiler_publish_docker_images.yml | |
branches: | |
- 'main' | |
- 'force-docker-images' | |
env: | |
ACTION_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
SLACK_CHANNEL: ${{ secrets.SLACK_CHANNEL }} | |
SLACK_USERNAME: ${{ secrets.BOT_USERNAME }} | |
SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} | |
THIS_FILE: .github/workflows/concrete_compiler_publish_docker_images.yml | |
concurrency: | |
group: concrete_compiler_publich_docker_images | |
cancel-in-progress: true | |
jobs: | |
setup-instance: | |
runs-on: ubuntu-latest | |
outputs: | |
runner-name: ${{ steps.start-instance.outputs.label }} | |
steps: | |
- name: Start instance | |
id: start-instance | |
uses: zama-ai/slab-github-runner@447a2d0fd2d1a9d647aa0d0723a6e9255372f261 | |
with: | |
mode: start | |
github-token: ${{ secrets.SLAB_ACTION_TOKEN }} | |
slab-url: ${{ secrets.SLAB_BASE_URL }} | |
job-secret: ${{ secrets.JOB_SECRET }} | |
backend: aws | |
profile: cpu-test | |
compiler-image: | |
needs: [setup-instance, hpx-image, cuda-image] | |
runs-on: ${{ needs.setup-instance.outputs.runner-name }} | |
env: | |
image: ghcr.io/zama-ai/concrete-compiler | |
dockerfile: docker/Dockerfile.concrete-compiler-env | |
steps: | |
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
with: | |
fetch-depth: 0 | |
submodules: recursive | |
- name: Login to Registry | |
run: echo "${{ secrets.GHCR_PASSWORD }}" | docker login -u ${{ secrets.GHCR_LOGIN }} --password-stdin ghcr.io | |
# label was initially a need from the frontend CI | |
- name: Build Image | |
run: | | |
DOCKER_BUILDKIT=1 docker build --no-cache \ | |
--label "commit-sha=${{ github.sha }}" -t ${{ env.image }} -f ${{ env.dockerfile }} . | |
# disabled because of https://github.com/aquasecurity/trivy/discussions/7668 | |
# - name: Run Trivy vulnerability scanner | |
# uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # 0.28.0 | |
# with: | |
# image-ref: '${{ matrix.image }}' | |
# format: 'table' | |
# exit-code: '1' | |
# ignore-unfixed: true | |
# vuln-type: 'os,library' | |
# severity: 'CRITICAL,HIGH' | |
- name: Tag and Publish Image | |
run: | | |
docker image tag ${{ env.image }} ${{ env.image }}:${{ github.sha }} | |
docker image push ${{ env.image }}:latest | |
docker image push ${{ env.image }}:${{ github.sha }} | |
- name: Tag and Publish Release Image | |
if: startsWith(github.ref, 'refs/tags/v') | |
run: | | |
docker image tag ${{ env.image }} ${{ env.image }}:${{ github.ref_name }} | |
docker image push ${{ env.image }}:${{ github.ref_name }} | |
- name: Slack Notification | |
if: ${{ failure() && github.ref == 'refs/heads/main' }} | |
continue-on-error: true | |
uses: rtCamp/action-slack-notify@4e5fb42d249be6a45a298f3c9543b111b02f7907 | |
env: | |
SLACK_COLOR: ${{ job.status }} | |
SLACK_MESSAGE: "compiler-image finished with status: ${{ job.status }}. (${{ env.ACTION_RUN_URL }})" | |
hpx-image: | |
needs: [setup-instance] | |
runs-on: ${{ needs.setup-instance.outputs.runner-name }} | |
env: | |
image: ghcr.io/zama-ai/hpx | |
dockerfile: docker/Dockerfile.hpx-env | |
steps: | |
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
with: | |
fetch-depth: 0 | |
- name: Get changed files | |
id: changed-files | |
uses: tj-actions/changed-files@e9772d140489982e0e3704fea5ee93d536f1e275 # v44.5.24 | |
- name: Login | |
id: login | |
if: contains(steps.changed-files.outputs.modified_files, '${{ env.dockerfile }}') || contains(steps.changed-files.outputs.modified_files, env.THIS_FILE) | |
run: echo "${{ secrets.GHCR_PASSWORD }}" | docker login -u ${{ secrets.GHCR_LOGIN }} --password-stdin ghcr.io | |
- name: Build | |
if: ${{ steps.login.conclusion != 'skipped' }} | |
run: docker build -t "${{ env.image }}" -f ${{ env.dockerfile }} . | |
# disabled because of https://github.com/aquasecurity/trivy/discussions/7668 | |
# - name: Run Trivy vulnerability scanner | |
# if: ${{ steps.login.conclusion != 'skipped' }} | |
# uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # 0.28.0 | |
# with: | |
# image-ref: '${{ env.IMAGE }}' | |
# format: 'table' | |
# exit-code: '1' | |
# ignore-unfixed: true | |
# vuln-type: 'os,library' | |
# severity: 'CRITICAL,HIGH' | |
- name: Publish | |
if: ${{ steps.login.conclusion != 'skipped' }} | |
run: docker push "${{ env.image }}:latest" | |
- name: Slack Notification | |
if: ${{ failure() && github.ref == 'refs/heads/main' }} | |
continue-on-error: true | |
uses: rtCamp/action-slack-notify@4e5fb42d249be6a45a298f3c9543b111b02f7907 | |
env: | |
SLACK_COLOR: ${{ job.status }} | |
SLACK_MESSAGE: "hpx-image finished with status: ${{ job.status }}. (${{ env.ACTION_RUN_URL }})" | |
cuda-image: | |
needs: [setup-instance] | |
runs-on: ${{ needs.setup-instance.outputs.runner-name }} | |
env: | |
image: ghcr.io/zama-ai/cuda | |
strategy: | |
matrix: | |
include: | |
- name: cuda-12-3 | |
tag: 12-3 | |
dockerfile: docker/Dockerfile.cuda-123-env | |
- name: cuda-11-8 | |
tag: 11-8 | |
dockerfile: docker/Dockerfile.cuda-118-env | |
steps: | |
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
with: | |
fetch-depth: 0 | |
- name: Set up env | |
run: | | |
echo "HOME=/home/ubuntu" >> "${GITHUB_ENV}" | |
- name: Get changed files | |
id: changed-files | |
uses: tj-actions/changed-files@e9772d140489982e0e3704fea5ee93d536f1e275 # v44.5.24 | |
- name: Login | |
id: login | |
# from the docs: The jobs.<job_id>.if condition is evaluated before jobs.<job_id>.strategy.matrix is applied. So we can't just use matrix.dockerfile | |
# so we have to build both images if one of the two files change, or we will have to split this into two | |
# https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idif | |
if: contains(steps.changed-files.outputs.modified_files, 'docker/Dockerfile.cuda-118-env') || contains(steps.changed-files.outputs.modified_files, 'docker/Dockerfile.cuda-123-env') || contains(steps.changed-files.outputs.modified_files, env.THIS_FILE) | |
run: echo "${{ secrets.GHCR_PASSWORD }}" | docker login -u ${{ secrets.GHCR_LOGIN }} --password-stdin ghcr.io | |
- name: Build Tag and Publish | |
if: ${{ steps.login.conclusion != 'skipped' }} | |
run: | | |
docker build -t "${{ env.image }}" -f ${{ matrix.dockerfile }} . | |
docker image tag "${{ env.image }}" "${{ env.image }}:${{ matrix.tag }}" | |
docker push "${{ env.image }}:${{ matrix.tag }}" | |
# disabled because of https://github.com/aquasecurity/trivy/discussions/7668 | |
# - name: Run Trivy vulnerability scanner | |
# if: ${{ steps.login.conclusion != 'skipped' }} | |
# uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # 0.28.0 | |
# with: | |
# image-ref: '${{ env.image }}' | |
# format: 'table' | |
# exit-code: '1' | |
# ignore-unfixed: true | |
# vuln-type: 'os,library' | |
# severity: 'CRITICAL,HIGH' | |
- name: Push Latest Image | |
if: ${{ steps.login.conclusion != 'skipped' && matrix.tag == '11-8' }} | |
run: docker push "${{ env.image }}:latest" | |
- name: Slack Notification | |
if: ${{ failure() && github.ref == 'refs/heads/main' }} | |
continue-on-error: true | |
uses: rtCamp/action-slack-notify@4e5fb42d249be6a45a298f3c9543b111b02f7907 | |
env: | |
SLACK_COLOR: ${{ job.status }} | |
SLACK_MESSAGE: "cuda-image finished with status: ${{ job.status }}. (${{ env.ACTION_RUN_URL }})" |