diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index e7e90065..1a90608a 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -1,55 +1,57 @@ -name: Publish - -on: - release: - types: [published] - -permissions: - id-token: write - contents: read - -env: - AWS_REGION: us-east-1 - ECR_REPOSITORY: reporting/oauth2-proxy - -jobs: - Publish: - runs-on: ubuntu-22.04 - name: Publish to Amazon ECR - steps: - - name: Checkout - uses: actions/checkout@v4 - - - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0 - with: - role-to-assume: ${{ secrets.PICS_ECR_ROLE_ARN }} - aws-region: ${{ env.AWS_REGION }} - - - name: Login to Amazon ECR - id: login-ecr - uses: aws-actions/amazon-ecr-login@062b18b96a7aff071d4dc91bc00c4c1a7945b076 # v2.0.1 - -aws ecr create-repository \ - --repository-name "${ECR_REPOSITORY}" \ - --image-scanning-configuration scanOnPush=true \ - >/dev/null 2>&1 || aws ecr describe-repositories --repository-names "${ECR_REPOSITORY}" >/dev/null - - - name: Enforce image tag immutability - run: | - aws ecr put-image-tag-mutability \ - --repository-name "${ECR_REPOSITORY}" \ - --image-tag-mutability IMMUTABLE - - - name: Apply ECR delete-protection policy - run: | - aws ecr set-repository-policy \ - --repository-name "${ECR_REPOSITORY}" \ - --policy-text '{"Version":"2012-10-17","Statement":[{"Sid":"DenyDeleteRepository","Effect":"Deny","Principal":"*","Action":"ecr:DeleteRepository"}]}' - - - name: Publish Docker image - uses: docker/build-push-action@v4 - with: - context: ${{ github.workspace }} - push: true -tags: ${{ steps.login-ecr.outputs.registry }}/${{ env.ECR_REPOSITORY }}:${{ github.event.release.tag_name }} +name: Publish + +on: + release: + types: [published] + +permissions: + id-token: write + contents: read + +env: + AWS_REGION: us-east-1 + ECR_REPOSITORY: reporting/oauth2-proxy + +jobs: + Publish: + runs-on: ubuntu-22.04 + name: Publish to Amazon ECR + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0 + with: + role-to-assume: ${{ secrets.PICS_ECR_ROLE_ARN }} + aws-region: ${{ env.AWS_REGION }} + + - name: Login to Amazon ECR + id: login-ecr + uses: aws-actions/amazon-ecr-login@062b18b96a7aff071d4dc91bc00c4c1a7945b076 # v2.0.1 + - name: Create ECR repository (if it does not exist) + run: | + aws ecr create-repository \ + --repository-name "${ECR_REPOSITORY}" \ + --image-scanning-configuration scanOnPush=false \ + >/dev/null 2>&1 || aws ecr describe-repositories --repository-names "${ECR_REPOSITORY}" >/dev/null + + + - name: Enforce image tag immutability + run: | + aws ecr put-image-tag-mutability \ + --repository-name "${ECR_REPOSITORY}" \ + --image-tag-mutability IMMUTABLE + + - name: Apply ECR delete-protection policy + run: | + aws ecr set-repository-policy \ + --repository-name "${ECR_REPOSITORY}" \ + --policy-text '{"Version":"2012-10-17","Statement":[{"Sid":"DenyDeleteRepository","Effect":"Deny","Principal":"*","Action":"ecr:DeleteRepository"}]}' + + - name: Publish Docker image + uses: docker/build-push-action@v4 + with: + context: ${{ github.workspace }} + push: true + tags: ${{ steps.login-ecr.outputs.registry }}/${{ env.ECR_REPOSITORY }}:${{ github.event.release.tag_name }}