name: Build and Push Docker Image # 触发: # - push 到 main: 覆盖刷新 :latest + :sha(每次提交可追溯) # - 打 v* tag: 额外产出带版本号的镜像(如 :v0.1.43), 便于固定回溯 # - 手动: 网页 Actions → Run workflow on: push: branches: [main] tags: ['v*'] workflow_dispatch: env: REGISTRY: ghcr.io IMAGE_NAME: ${{ github.repository }} jobs: build-and-push: runs-on: ubuntu-latest permissions: contents: read packages: write steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up QEMU uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to the Container registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata (tags, labels) for Docker id: meta uses: docker/metadata-action@v5 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | type=raw,value=latest type=sha,prefix= type=ref,event=tag - name: Build and push Docker image uses: docker/build-push-action@v6 with: context: . push: true platforms: linux/amd64,linux/arm64 # GitHub runner 在海外, 关掉国内镜像源(USE_CN_MIRROR=0) # 让构建直连官方 npm/PyPI, 反而更快更稳; # 本地/国内手动 docker build 仍走 Dockerfile 默认的 CN 镜像。 build-args: | USE_CN_MIRROR=0 tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max