.gitea/workflows/redhat_build.yml aktualisiert
This commit is contained in:
@@ -86,13 +86,9 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
sudo apt-get update && sudo apt-get install -y buildah fuse-overlayfs
|
sudo apt-get update && sudo apt-get install -y buildah fuse-overlayfs
|
||||||
|
|
||||||
# 5. Image direkt mit Buildah bauen (nutzt Bash-Array gegen Word-Splitting)
|
# 5. Image mit Buildah bauen (nutzt volle Kernel-Isolierung im privilegierten Runner)
|
||||||
- name: Build Image with Buildah
|
- name: Build Image with Buildah
|
||||||
run: |
|
run: |
|
||||||
# Systemweite Containers-Konfig auf chroot festlegen
|
|
||||||
sudo mkdir -p /etc/containers
|
|
||||||
printf '[containers]\nisolation = "chroot"\n' | sudo tee /etc/containers/containers.conf
|
|
||||||
|
|
||||||
# Metadata-Labels sauber in ein Bash-Array einlesen (schützt Leerzeichen)
|
# Metadata-Labels sauber in ein Bash-Array einlesen (schützt Leerzeichen)
|
||||||
BUILD_ARGS=()
|
BUILD_ARGS=()
|
||||||
while IFS= read -r line; do
|
while IFS= read -r line; do
|
||||||
@@ -101,9 +97,8 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
done <<< "${{ steps.metadata.outputs.labels }}"
|
done <<< "${{ steps.metadata.outputs.labels }}"
|
||||||
|
|
||||||
# Buildah ausführen
|
# Einfacher, nativer Buildah-Aufruf als root
|
||||||
buildah bud \
|
sudo buildah bud \
|
||||||
--isolation chroot \
|
|
||||||
--format oci \
|
--format oci \
|
||||||
"${BUILD_ARGS[@]}" \
|
"${BUILD_ARGS[@]}" \
|
||||||
-t "${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" \
|
-t "${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" \
|
||||||
@@ -112,7 +107,9 @@ jobs:
|
|||||||
# 6. In lokales OCI-Verzeichnis exportieren
|
# 6. In lokales OCI-Verzeichnis exportieren
|
||||||
- name: Export Image to OCI Layout
|
- name: Export Image to OCI Layout
|
||||||
run: |
|
run: |
|
||||||
buildah push ${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }} oci:./oci-image
|
sudo buildah push ${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }} oci:./oci-image
|
||||||
|
# Verzeichnisrechte für nachfolgende Runner-Schritte freigeben
|
||||||
|
sudo chown -R $(id -u):$(id -g) ./oci-image
|
||||||
|
|
||||||
# 7. Chunkah via Project Bluefin Action ausführen
|
# 7. Chunkah via Project Bluefin Action ausführen
|
||||||
- name: Process OCI Image with Chunkah
|
- name: Process OCI Image with Chunkah
|
||||||
@@ -170,4 +167,4 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
echo "Bereinige temporäre Dateien und Buildah-Storage..."
|
echo "Bereinige temporäre Dateien und Buildah-Storage..."
|
||||||
rm -rf ./oci-image /tmp/digest.txt || true
|
rm -rf ./oci-image /tmp/digest.txt || true
|
||||||
buildah rmi --all --force || true
|
sudo buildah rmi --all --force || true
|
||||||
Reference in New Issue
Block a user