-
Notifications
You must be signed in to change notification settings - Fork 0
152 lines (133 loc) · 5.52 KB
/
Copy pathpublish-container.yml
File metadata and controls
152 lines (133 loc) · 5.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
name: Publish Container
on:
push:
branches:
- main
tags:
- 'v*' # Match version tags like v2.1.17
pull_request:
branches:
- main
workflow_dispatch:
inputs:
version:
description: 'Claude Code version to build (e.g., 2.1.23)'
required: false
type: string
update_aliases:
description: 'Also update alias tags (latest, vX, vX.Y). Disable to only push the exact version tag.'
required: false
type: boolean
default: true
workflow_call:
inputs:
version:
description: 'Claude Code version to build (e.g., 2.1.23)'
required: true
type: string
update_aliases:
description: 'Also update alias tags (latest, vX, vX.Y). Disable to only push the exact version tag.'
required: false
type: boolean
default: true
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
verify-source:
name: Verify Claude Code Source URL
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Verify GCS bucket URL
run: |
chmod +x .claude/skills/verifying-claude-source/scripts/verify-source.sh
.claude/skills/verifying-claude-source/scripts/verify-source.sh
build-and-push:
name: Build and Push Container
runs-on: ubuntu-latest
needs: verify-source
permissions:
contents: read
packages: write
id-token: write
attestations: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch,enable=${{ inputs.version == '' }}
type=ref,event=pr,enable=${{ inputs.version == '' }}
type=semver,pattern={{version}},enable=${{ inputs.version == '' }}
type=semver,pattern={{major}}.{{minor}},enable=${{ inputs.version == '' }}
type=semver,pattern={{major}},enable=${{ inputs.version == '' }}
type=raw,value=latest,enable=${{ inputs.version == '' && github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }}
# Tags for version input (workflow_dispatch / workflow_call)
type=semver,pattern={{version}},value=v${{ inputs.version }},enable=${{ inputs.version != '' }}
type=semver,pattern={{major}}.{{minor}},value=v${{ inputs.version }},enable=${{ inputs.version != '' && inputs.update_aliases }}
type=semver,pattern={{major}},value=v${{ inputs.version }},enable=${{ inputs.version != '' && inputs.update_aliases }}
type=raw,value=latest,enable=${{ inputs.version != '' && inputs.update_aliases }}
labels: |
org.opencontainers.image.title=Claude Code Container
org.opencontainers.image.description=Containerized Claude Code CLI with VSIX extension
- name: Build and push Docker image
id: build
uses: docker/build-push-action@v5
with:
context: .
platforms: linux/amd64,linux/arm64
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: |
CLAUDE_VERSION=${{ inputs.version || 'latest' }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Verify VSIX in built image
continue-on-error: true
if: startsWith(github.ref, 'refs/tags/v') || inputs.version != ''
run: |
# Extract first tag from metadata
IMAGE_TAG=$(echo "${{ steps.meta.outputs.tags }}" | head -1)
echo "Verifying VSIX in image: ${IMAGE_TAG}"
# Verify VSIX exists
docker run --rm --entrypoint ls "${IMAGE_TAG}" -lh /opt/claude-code/claude-code.vsix
# Verify VSIX is valid
docker run --rm --entrypoint file "${IMAGE_TAG}" /opt/claude-code/claude-code.vsix
echo "VSIX verification successful"
- name: Verify Windows binary in built image
continue-on-error: true
if: startsWith(github.ref, 'refs/tags/v') || inputs.version != ''
run: |
# Extract first tag from metadata
IMAGE_TAG=$(echo "${{ steps.meta.outputs.tags }}" | head -1)
echo "Verifying Windows binary in image: ${IMAGE_TAG}"
if docker run --rm --entrypoint test "${IMAGE_TAG}" -f /opt/claude-code/win32-x64/claude.exe; then
docker run --rm --entrypoint ls "${IMAGE_TAG}" -lh /opt/claude-code/win32-x64/claude.exe
echo "Windows binary verification successful"
else
echo "::warning::Windows binary missing from image ${IMAGE_TAG} (not published for this version, or download failed)"
fi
- name: Generate artifact attestation
if: github.event_name != 'pull_request'
uses: actions/attest-build-provenance@v1
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
subject-digest: ${{ steps.build.outputs.digest }}
push-to-registry: true