40 lines
1.3 KiB
YAML
40 lines
1.3 KiB
YAML
---
|
|||
|
|
# Dockerfile ничего не компилирует: в образ копируется закоммиченный
|
||
|
|
# bin/validator-agent. Не даём выкатить бинарник, не совпадающий с суммой.
|
||
|
|
- name: Check bin/validator-agent against SHA256SUMS
|
||
|
|
ansible.builtin.shell: |
|
||
|
|
set -o pipefail
|
||
|
|
grep -E '[[:space:]]validator-agent$' SHA256SUMS | sha256sum -c -
|
||
|
|
args:
|
||
|
|
chdir: "{{ repo_dir }}/bin"
|
||
|
|
executable: /bin/bash
|
||
|
|
changed_when: false
|
||
|
|
|
||
|
|
# Контекст сборки — корень репозитория (так и в SETUP.md). Слои кэшируются,
|
||
|
|
# при смене bin/ образ пересобирается сам.
|
||
|
|
- name: Build the image
|
||
|
|
ansible.builtin.command:
|
||
|
|
argv:
|
||
|
|
- docker
|
||
|
|
- build
|
||
|
|
- --platform
|
||
|
|
- "{{ platform }}"
|
||
|
|
- --label
|
||
|
|
- "git.rev={{ rev_after.stdout }}"
|
||
|
|
- --label
|
||
|
|
- deployed.by=ansible
|
||
|
|
- -t
|
||
|
|
- "{{ image_ref }}"
|
||
|
|
- -f
|
||
|
|
- "{{ dockerfile }}"
|
||
|
|
- .
|
||
|
|
chdir: "{{ repo_dir }}"
|
||
|
|
|
||
|
|
- name: Tag the image as latest
|
||
|
|
ansible.builtin.command: "docker tag {{ image_ref }} {{ image_name }}:latest"
|
||
|
|
|
||
|
|
- name: Read the image id
|
||
|
|
ansible.builtin.command:
|
||
|
|
argv: [docker, image, inspect, --format, "{% raw %}{{.Id}}{% endraw %}", "{{ image_ref }}"]
|
||
|
|
changed_when: false
|
||
|
|
register: built_image
|