Skip to content

Commit 4320b3c

Browse files
authored
Merge pull request #13 from OpenIPC/ci-docker-skip-without-secrets
ci: keep master green — skip Docker publish when secrets are absent
2 parents 51e6961 + a07d179 commit 4320b3c

2 files changed

Lines changed: 51 additions & 29 deletions

File tree

‎.github/workflows/main.yml‎

Lines changed: 46 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,46 @@
1-
name: ci
2-
on:
3-
push:
4-
branches:
5-
- master
6-
workflow_dispatch:
7-
jobs:
8-
docker:
9-
runs-on: ubuntu-latest
10-
# Publish only from master, even for manual workflow_dispatch runs, so a
11-
# dispatch from a feature branch can't overwrite the :latest image.
12-
if: github.ref == 'refs/heads/master'
13-
steps:
14-
- name: Set up QEMU
15-
uses: docker/setup-qemu-action@v1
16-
- name: Set up Docker Buildx
17-
uses: docker/setup-buildx-action@v1
18-
- name: Login to DockerHub
19-
uses: docker/login-action@v1
20-
with:
21-
username: ${{ secrets.DOCKERHUB_USERNAME }}
22-
password: ${{ secrets.DOCKERHUB_TOKEN }}
23-
- name: Build and push
24-
uses: docker/build-push-action@v2
25-
with:
26-
push: true
27-
tags: braunbearded/python-dvr:latest,braunbearded/python-dvr:${{ github.sha }}
1+
name: ci
2+
on:
3+
push:
4+
branches:
5+
- master
6+
workflow_dispatch:
7+
jobs:
8+
docker:
9+
runs-on: ubuntu-latest
10+
# Publish only from master, even for manual workflow_dispatch runs, so a
11+
# dispatch from a feature branch can't overwrite the :latest image.
12+
if: github.ref == 'refs/heads/master'
13+
steps:
14+
# Without DockerHub credentials the publish can't run; skip it (and keep
15+
# the job green) instead of failing every push to master. The secrets are
16+
# scoped to this step only (the login action takes them via its inputs).
17+
- name: Check DockerHub credentials
18+
id: creds
19+
env:
20+
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
21+
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
22+
run: |
23+
if [ -n "$DOCKERHUB_USERNAME" ] && [ -n "$DOCKERHUB_TOKEN" ]; then
24+
echo "present=true" >> "$GITHUB_OUTPUT"
25+
else
26+
echo "present=false" >> "$GITHUB_OUTPUT"
27+
echo "::notice::DOCKERHUB_USERNAME/DOCKERHUB_TOKEN are not set; skipping the image publish."
28+
fi
29+
- name: Set up QEMU
30+
if: steps.creds.outputs.present == 'true'
31+
uses: docker/setup-qemu-action@v1
32+
- name: Set up Docker Buildx
33+
if: steps.creds.outputs.present == 'true'
34+
uses: docker/setup-buildx-action@v1
35+
- name: Login to DockerHub
36+
if: steps.creds.outputs.present == 'true'
37+
uses: docker/login-action@v1
38+
with:
39+
username: ${{ secrets.DOCKERHUB_USERNAME }}
40+
password: ${{ secrets.DOCKERHUB_TOKEN }}
41+
- name: Build and push
42+
if: steps.creds.outputs.present == 'true'
43+
uses: docker/build-push-action@v2
44+
with:
45+
push: true
46+
tags: braunbearded/python-dvr:latest,braunbearded/python-dvr:${{ github.sha }}

‎CLAUDE.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,11 @@ own `requirements.txt` and is self-contained.
4747
### Docker / CI
4848

4949
`Dockerfile` runs `download-local-files.py`. `.github/workflows/main.yml`
50-
builds and pushes that image to Docker Hub on every branch push;
51-
`codeql.yml` runs CodeQL Python analysis on master.
50+
builds and pushes that image to Docker Hub on pushes to `master` (only
51+
when the `DOCKERHUB_USERNAME`/`DOCKERHUB_TOKEN` secrets are set — it skips
52+
the publish otherwise); `codeql.yml` runs CodeQL Python analysis on
53+
master. `.github/workflows/test.yml` lint/smoke-tests the library on
54+
pushes and PRs.
5255

5356
## Architecture
5457

0 commit comments

Comments
 (0)