plugin-barman-cloud/.github/workflows/ci.yml
Marco Nenciarini bc4f0c498b ci: run image publish in a separate parallel job
Neither task depends on the other's output: task ci runs lint,
tests, e2e, and docs, while task publish builds and pushes the
multi-arch images. Running them as sequential steps in one job
only adds their durations. Splitting publish into its own job
lets it run alongside ci instead, and lets each job carry only
the permissions it actually needs: ci never writes to the
registry, and neither task touches repository contents, so only
packages: write on the publish job remains.

QEMU is only needed for publish, since it's the only job that
builds non-native (arm64) platforms; ci's e2e-ephemeral image
build is amd64-only. The disk cleanup steps aren't needed for
publish either: it only builds two lean multi-arch images, well
within the free disk space available even on the default
ubuntu-latest runner.

Note that publishing testing images no longer waits on ci
passing, since gating it away would remove the parallelism this
is meant to gain.

Signed-off-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
2026-07-21 15:02:53 +02:00

90 lines
2.8 KiB
YAML

name: CI
on:
pull_request:
workflow_dispatch:
permissions: read-all
jobs:
ci:
runs-on: ${{ vars.CI_RUNNERS || 'ubuntu-latest' }}
permissions:
contents: read
steps:
- name: Cleanup Disk
if: vars.CI_RUNNERS == '' || vars.CI_RUNNERS == 'ubuntu-latest'
uses: jlumbroso/free-disk-space@v1.3.1
with:
android: true
dotnet: true
haskell: true
tool-cache: true
large-packages: false
swap-storage: false
- name: Cleanup docker cache
if: vars.CI_RUNNERS == '' || vars.CI_RUNNERS == 'ubuntu-latest'
run: |
echo "-------------Disk info before cleanup----------------"
df -h
echo "-----------------------------------------------------"
docker system prune -a -f
echo "-------------Disk info after cleanup----------------"
df -h
echo "-----------------------------------------------------"
- name: Checkout
uses: actions/checkout@v7.0.1
# We need the full history for the commitlint task
with:
fetch-depth: 0
ref: ${{ github.event.pull_request.head.sha }}
- name: Install Task
uses: arduino/setup-task@v3.0.0
- name: Install Dagger
env:
# renovate: datasource=github-tags depName=dagger/dagger versioning=semver
DAGGER_VERSION: 0.21.7
run: |
curl -L https://dl.dagger.io/dagger/install.sh | BIN_DIR=$HOME/.local/bin sh
- name: Run CI task
run: |
task ci
publish:
runs-on: ${{ vars.CI_RUNNERS || 'ubuntu-latest' }}
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha }}
- name: Install QEMU static binaries
uses: docker/setup-qemu-action@v4
- name: Install Task
uses: arduino/setup-task@v3.0.0
- name: Install Dagger
env:
# renovate: datasource=github-tags depName=dagger/dagger versioning=semver
DAGGER_VERSION: 0.21.7
run: |
curl -L https://dl.dagger.io/dagger/install.sh | BIN_DIR=$HOME/.local/bin sh
- name: Write manifest
run: |
task manifest
- name: Publish images
if: |
github.event_name == 'workflow_dispatch' ||
github.event.pull_request.head.repo.full_name == github.repository
env:
REGISTRY_USER: ${{ github.actor }}
REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
run: |
task publish
- name: Attach manifest to workflow run
uses: actions/upload-artifact@v7
with:
name: manifest.yaml
path: ./manifest.yaml