Update docs, Dockerfile, and CI for container registry support

Expanded documentation in both English and Chinese READMEs to include detailed container registry acceleration usage and deployment instructions. Refactored Dockerfile to use a multi-stage build with workerd for self-hosted deployment. Improved .dockerignore for cleaner builds. Updated GitHub Actions workflows to refine path ignores and metadata extraction. Added config.capnp for workerd configuration. Removed obsolete .html file and enhanced CLAUDE.md with comprehensive architecture and development guidance.
This commit is contained in:
xixu-me committed 2025-11-16 17:46:48 +08:00
1 parent 11adfba201
commit 93c8e51fb1
9 files changed
+886 -728

No files matched your search

+4
View File
@@ -13,6 +13,10 @@ on:
- '.editorconfig'
- '.vscode/**'
- 'docs/**'
- '.prettierrc*'
- '.eslintrc*'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE/**'
workflow_dispatch:
jobs:
+24 -60
View File
@@ -4,28 +4,33 @@ on:
push:
branches:
- main
- develop
tags:
- 'v*'
paths-ignore:
- '**.md'
- 'docs/**'
- 'test/**'
- 'scripts/**'
- 'LICENSE'
- '.gitignore'
- '.editorconfig'
- 'LICENSE'
- '.vscode/**'
- 'docs/**'
- '.prettierrc*'
- '.eslintrc*'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE/**'
pull_request:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
- 'test/**'
- 'scripts/**'
- 'LICENSE'
- '.gitignore'
- '.editorconfig'
- 'LICENSE'
- '.vscode/**'
- 'docs/**'
- '.prettierrc*'
- '.eslintrc*'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE/**'
workflow_dispatch:
env:
@@ -35,30 +40,26 @@ env:
jobs:
build-and-push:
runs-on: ubuntu-latest
outputs:
image-tags: ${{ steps.meta.outputs.tags }}
image-digest: ${{ steps.build-and-push.outputs.digest }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Container Registry
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
@@ -69,61 +70,24 @@ jobs:
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=semver,pattern={{major}}
type=sha,prefix={{branch}}-
type=sha
type=raw,value=latest,enable={{is_default_branch}}
- name: Build and push image
id: build-and-push
- name: Build and push Docker image
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
push: true
platforms: linux/amd64
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Generate artifact attestation
uses: actions/attest-build-provenance@v3
if: github.event_name != 'pull_request'
uses: actions/attest-build-provenance@v2
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
subject-digest: ${{ steps.build-and-push.outputs.digest }}
subject-digest: ${{ steps.meta.outputs.digest }}
push-to-registry: true
security-scan:
runs-on: ubuntu-latest
needs: build-and-push
if: github.event_name != 'pull_request'
permissions:
contents: read
packages: read
security-events: write
steps:
- name: Debug outputs
run: |
echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}"
echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}"
echo "Registry: ${{ env.REGISTRY }}"
echo "Image name: ${{ env.IMAGE_NAME }}"
- name: Set image for scanning
id: scan-image
run: |
FIRST_TAG=$(echo "${{ needs.build-and-push.outputs.image-tags }}" | head -n1)
echo "image-ref=${FIRST_TAG}" >> $GITHUB_OUTPUT
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ steps.scan-image.outputs.image-ref }}
format: 'sarif'
output: 'trivy-results.sarif'
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: 'trivy-results.sarif'