diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 61dca92..d60ecf9 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -2,7 +2,6 @@ name: CI - Lint, Test, and Push Docker Image on: push: - branches: [ "main" ] pull_request: branches: [ "main" ] schedule: @@ -48,17 +47,17 @@ jobs: - name: Checkout code uses: actions/checkout@v4 + - name: Setup melange + uses: chainguard-dev/actions/setup-melange@main + - name: Generate melange signing keypair - uses: chainguard-dev/actions/melange-keygen@main - with: - signing-key-path: melange.rsa + run: melange keygen melange.rsa - name: Build package with melange - uses: chainguard-dev/actions/melange-build@main - with: - config: melange.yaml - signing-key-path: melange.rsa - archs: x86_64,aarch64 + run: | + melange build melange.yaml \ + --signing-key melange.rsa \ + --arch x86_64,aarch64 - name: Log in to GHCR uses: docker/login-action@v3 @@ -75,28 +74,3 @@ jobs: tag: ghcr.io/k2patel/apcupsd-client:latest keyring-append: melange.rsa.pub - build-docker: - runs-on: ubuntu-latest - needs: lint-and-test - if: github.event_name != 'pull_request' - steps: - - name: Set Image name - run: | - echo "IMAGE_NAME=k2patel/apcupsd-client:latest" >> $GITHUB_ENV - - - name: Checkout code - uses: actions/checkout@v4 - - - name: Log in to Docker Hub - uses: docker/login-action@v3 - with: - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_TOKEN }} - - - name: Build the Docker image - id: build - run: | - docker build . -t ${{ env.IMAGE_NAME }} - - - name: Push the Docker image - run: docker push ${{ env.IMAGE_NAME }} diff --git a/apko.yaml b/apko.yaml index 3265158..ccefa1c 100644 --- a/apko.yaml +++ b/apko.yaml @@ -1,11 +1,11 @@ contents: repositories: - - https://dl-cdn.alpinelinux.org/alpine/edge/main - - https://dl-cdn.alpinelinux.org/alpine/edge/community + - https://dl-cdn.alpinelinux.org/alpine/v3.21/main + - https://dl-cdn.alpinelinux.org/alpine/v3.21/community - '@local ./packages' packages: - - alpine-baselayout - - busybox + - alpine-baselayout-data + - ca-certificates-bundle - python3 - apcupsd - apcupsd-client@local @@ -26,6 +26,6 @@ environment: REDIS_URL: "redis://redis:6379/0" entrypoint: - command: /usr/bin/start-server + command: /app/.venv/bin/python -m uvicorn app.main:app --host 0.0.0.0 --port 8000 work-dir: /app diff --git a/melange.yaml b/melange.yaml index 5a222d5..b1b2dcd 100644 --- a/melange.yaml +++ b/melange.yaml @@ -1,26 +1,22 @@ package: - name: apcupsd-client + name: apcupsd-client-build version: 1.0.0 epoch: 0 - description: FastAPI + Redis UPS monitoring dashboard + description: Build stage for apcupsd-client (not installed directly) copyright: - license: MIT environment: contents: repositories: - - https://dl-cdn.alpinelinux.org/alpine/edge/main - - https://dl-cdn.alpinelinux.org/alpine/edge/community + - https://dl-cdn.alpinelinux.org/alpine/v3.21/main + - https://dl-cdn.alpinelinux.org/alpine/v3.21/community packages: - alpine-baselayout - busybox - python3 - - python3-dev - py3-pip - py3-virtualenv - - gcc - - musl-dev - - libffi-dev pipeline: - name: Create virtualenv and install dependencies @@ -30,6 +26,7 @@ pipeline: python3 -m virtualenv "${{targets.destdir}}/app/.venv" "${{targets.destdir}}/app/.venv/bin/pip" install \ --no-cache-dir \ + --only-binary :all: \ -r requirements.prod.txt - name: Copy application source @@ -37,25 +34,36 @@ pipeline: set -ex cp -r app/ "${{targets.destdir}}/app/app/" - - name: Create entrypoint script - runs: | - set -ex - mkdir -p "${{targets.destdir}}/usr/bin" - cat > "${{targets.destdir}}/usr/bin/start-server" <<'SCRIPT' - #!/bin/sh - exec /app/.venv/bin/uvicorn app.main:app --host 0.0.0.0 --port 8000 - SCRIPT - chmod +x "${{targets.destdir}}/usr/bin/start-server" - - name: Fix virtualenv shebangs runs: | set -ex - # Rewrite shebangs so they reference the final installed path find "${{targets.destdir}}/app/.venv/bin" -type f -exec \ sed -i "s|${{targets.destdir}}||g" {} + -data: - - name: runtime-deps - items: - python3: python3 - apcupsd: apcupsd + - name: Strip build artifacts from virtualenv + runs: | + set -ex + rm -rf "${{targets.destdir}}/app/.venv/bin/pip"* + rm -rf "${{targets.destdir}}/app/.venv/bin/wheel"* + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/pip" + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/pip-*" + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/setuptools" + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/setuptools-*" + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/wheel" + rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/wheel-*" + find "${{targets.destdir}}/app/.venv" -name "__pycache__" -type d -exec rm -rf {} + 2>/dev/null || true + find "${{targets.destdir}}/app/.venv" -name "*.pyc" -delete 2>/dev/null || true + +subpackages: + - name: apcupsd-client + description: FastAPI + Redis UPS monitoring dashboard + options: + no-depends: true + dependencies: + runtime: + - python3 + pipeline: + - runs: | + set -ex + mkdir -p "${{targets.subpkgdir}}" + mv "${{targets.destdir}}/app" "${{targets.subpkgdir}}/app"