fi CI image step

AuthorKonata <konata@posteo.jp>
Date
Commit1417af941c5d9564dba8f55c47b06c59bd87374f
Parenta443c03
1 file changed, 15 insertions(+), 1 deletion(-)
▾M.hearthforge-ci.toml
@@ -126,8 +126,22 @@ mkdir -p ci-bin
cp "${CARGO_TARGET_DIR}/release/filebrowser-ng" ci-bin/filebrowser-ng
echo "$REGISTRY_PASSWORD" | podman-remote login "${CI_REGISTRY%%/*}" -u admin --password-stdin
# A remote build sends a seccomp profile path that the server opens. Alpine
# ships one at /etc/containers/seccomp.json and podman picks it over the
# /usr/share copy, but the server has only the latter. Ask the server for its
# own path. An empty answer means no profile can be named, so the build runs
# unconfined rather than failing.
prof=$(podman-remote info --format '{{.Host.Security.SECCOMPProfilePath}}' 2>/dev/null || true)
if [ -n "$prof" ]; then
seccomp="seccomp=$prof"
else
seccomp="seccomp=unconfined"
fi
img="$CI_REGISTRY:$CI_COMMIT_SHORT_SHA"
podman-remote build -f Containerfile -t "$img" --build-arg BIN_STAGE=prebuilt .
podman-remote build --security-opt "$seccomp" \
-f Containerfile -t "$img" --build-arg BIN_STAGE=prebuilt .
podman-remote push "$img"
if [ -n "${CI_COMMIT_TAG:-}" ]; then