Update docs, Dockerfile, and CI for container registry support
Expanded documentation in both English and Chinese READMEs to include detailed container registry acceleration usage and deployment instructions. Refactored Dockerfile to use a multi-stage build with workerd for self-hosted deployment. Improved .dockerignore for cleaner builds. Updated GitHub Actions workflows to refine path ignores and metadata extraction. Added config.capnp for workerd configuration. Removed obsolete .html file and enhanced CLAUDE.md with comprehensive architecture and development guidance.
This commit is contained in:
1 parent
11adfba201
commit
93c8e51fb1
9 files changed
+886
-728
No files matched your search
@@ -13,6 +13,10 @@ on:
|
||||
- '.editorconfig'
|
||||
- '.vscode/**'
|
||||
- 'docs/**'
|
||||
- '.prettierrc*'
|
||||
- '.eslintrc*'
|
||||
- '.github/ISSUE_TEMPLATE/**'
|
||||
- '.github/PULL_REQUEST_TEMPLATE/**'
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
|
||||
+24
-60
@@ -4,28 +4,33 @@ on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- develop
|
||||
tags:
|
||||
- 'v*'
|
||||
paths-ignore:
|
||||
- '**.md'
|
||||
- 'docs/**'
|
||||
- 'test/**'
|
||||
- 'scripts/**'
|
||||
- 'LICENSE'
|
||||
- '.gitignore'
|
||||
- '.editorconfig'
|
||||
- 'LICENSE'
|
||||
- '.vscode/**'
|
||||
- 'docs/**'
|
||||
- '.prettierrc*'
|
||||
- '.eslintrc*'
|
||||
- '.github/ISSUE_TEMPLATE/**'
|
||||
- '.github/PULL_REQUEST_TEMPLATE/**'
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths-ignore:
|
||||
- '**.md'
|
||||
- 'docs/**'
|
||||
- 'test/**'
|
||||
- 'scripts/**'
|
||||
- 'LICENSE'
|
||||
- '.gitignore'
|
||||
- '.editorconfig'
|
||||
- 'LICENSE'
|
||||
- '.vscode/**'
|
||||
- 'docs/**'
|
||||
- '.prettierrc*'
|
||||
- '.eslintrc*'
|
||||
- '.github/ISSUE_TEMPLATE/**'
|
||||
- '.github/PULL_REQUEST_TEMPLATE/**'
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
@@ -35,30 +40,26 @@ env:
|
||||
jobs:
|
||||
build-and-push:
|
||||
runs-on: ubuntu-latest
|
||||
outputs:
|
||||
image-tags: ${{ steps.meta.outputs.tags }}
|
||||
image-digest: ${{ steps.build-and-push.outputs.digest }}
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v5
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Log in to Container Registry
|
||||
- name: Log in to GitHub Container Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ env.REGISTRY }}
|
||||
username: ${{ github.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Extract metadata
|
||||
- name: Extract metadata (tags, labels) for Docker
|
||||
id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
@@ -69,61 +70,24 @@ jobs:
|
||||
type=semver,pattern={{version}}
|
||||
type=semver,pattern={{major}}.{{minor}}
|
||||
type=semver,pattern={{major}}
|
||||
type=sha,prefix={{branch}}-
|
||||
type=sha
|
||||
type=raw,value=latest,enable={{is_default_branch}}
|
||||
|
||||
- name: Build and push image
|
||||
id: build-and-push
|
||||
- name: Build and push Docker image
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
file: ./Dockerfile
|
||||
push: true
|
||||
platforms: linux/amd64
|
||||
push: ${{ github.event_name != 'pull_request' }}
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
platforms: linux/amd64,linux/arm64
|
||||
cache-from: type=gha
|
||||
cache-to: type=gha,mode=max
|
||||
|
||||
- name: Generate artifact attestation
|
||||
uses: actions/attest-build-provenance@v3
|
||||
if: github.event_name != 'pull_request'
|
||||
uses: actions/attest-build-provenance@v2
|
||||
with:
|
||||
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
|
||||
subject-digest: ${{ steps.build-and-push.outputs.digest }}
|
||||
subject-digest: ${{ steps.meta.outputs.digest }}
|
||||
push-to-registry: true
|
||||
|
||||
security-scan:
|
||||
runs-on: ubuntu-latest
|
||||
needs: build-and-push
|
||||
if: github.event_name != 'pull_request'
|
||||
permissions:
|
||||
contents: read
|
||||
packages: read
|
||||
security-events: write
|
||||
|
||||
steps:
|
||||
- name: Debug outputs
|
||||
run: |
|
||||
echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}"
|
||||
echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}"
|
||||
echo "Registry: ${{ env.REGISTRY }}"
|
||||
echo "Image name: ${{ env.IMAGE_NAME }}"
|
||||
|
||||
- name: Set image for scanning
|
||||
id: scan-image
|
||||
run: |
|
||||
FIRST_TAG=$(echo "${{ needs.build-and-push.outputs.image-tags }}" | head -n1)
|
||||
echo "image-ref=${FIRST_TAG}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Run Trivy vulnerability scanner
|
||||
uses: aquasecurity/trivy-action@master
|
||||
with:
|
||||
image-ref: ${{ steps.scan-image.outputs.image-ref }}
|
||||
format: 'sarif'
|
||||
output: 'trivy-results.sarif'
|
||||
|
||||
- name: Upload Trivy scan results to GitHub Security tab
|
||||
uses: github/codeql-action/upload-sarif@v4
|
||||
if: always()
|
||||
with:
|
||||
sarif_file: 'trivy-results.sarif'
|
||||
Reference in new issue
Block a user