Add basic reverse proxy support #44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: docker-release | |
| on: | |
| pull_request: | |
| release: | |
| types: | |
| - published | |
| workflow_dispatch: | |
| env: | |
| REGISTRY: ghcr.io | |
| IMAGE_NAME: python-roborock/local_roborock_server | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: docker-release-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version-file: pyproject.toml | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v7 | |
| with: | |
| enable-cache: true | |
| - name: Install project | |
| run: uv sync --locked --extra dev | |
| - name: Run tests | |
| run: uv run pytest -q | |
| docker-validate: | |
| needs: test | |
| if: github.event_name == 'pull_request' || github.event_name == 'workflow_dispatch' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4 | |
| - name: Build Docker image | |
| uses: docker/build-push-action@v7 | |
| with: | |
| context: . | |
| file: ./Dockerfile | |
| platforms: linux/amd64 | |
| push: false | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| docker-release: | |
| needs: test | |
| if: github.event_name == 'release' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| packages: write | |
| attestations: write | |
| id-token: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version-file: pyproject.toml | |
| - name: Validate release tag matches package version | |
| shell: python | |
| run: | | |
| import re | |
| import tomllib | |
| from pathlib import Path | |
| tag = "${{ github.event.release.tag_name }}" | |
| pyproject = tomllib.loads(Path("pyproject.toml").read_text(encoding="utf-8")) | |
| project_version = str(pyproject["project"]["version"]).strip() | |
| init_text = Path("src/roborock_local_server/__init__.py").read_text(encoding="utf-8") | |
| match = re.search(r'__version__\s*=\s*"([^"]+)"', init_text) | |
| if match is None: | |
| raise SystemExit("Could not find __version__ in src/roborock_local_server/__init__.py") | |
| module_version = match.group(1).strip() | |
| expected_tag = f"v{project_version}" | |
| if module_version != project_version: | |
| raise SystemExit( | |
| f"Version mismatch: pyproject.toml={project_version}, __init__.py={module_version}" | |
| ) | |
| if tag != expected_tag: | |
| raise SystemExit(f"Git tag {tag} does not match package version {expected_tag}") | |
| - name: Log in to GHCR | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4 | |
| - name: Extract metadata | |
| id: meta | |
| uses: docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} | |
| flavor: latest=false | |
| tags: | | |
| type=semver,pattern={{version}},value=${{ github.event.release.tag_name }} | |
| type=semver,pattern={{major}}.{{minor}},value=${{ github.event.release.tag_name }} | |
| type=semver,pattern={{major}},value=${{ github.event.release.tag_name }} | |
| type=raw,value=latest,enable=${{ startsWith(github.event.release.tag_name, 'v') && !contains(github.event.release.tag_name, '-') }} | |
| type=sha,prefix=sha- | |
| labels: | | |
| org.opencontainers.image.title=roborock-local-server | |
| org.opencontainers.image.source=https://github.com/python-roborock/local_roborock_server | |
| org.opencontainers.image.description=Private Roborock HTTPS and MQTT stack for local LAN use | |
| org.opencontainers.image.licenses=MIT | |
| - name: Build and push Docker image | |
| id: push | |
| uses: docker/build-push-action@v7 | |
| with: | |
| context: . | |
| file: ./Dockerfile | |
| platforms: linux/amd64,linux/arm64 | |
| push: true | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| - name: Generate artifact attestation | |
| uses: actions/attest@v4 | |
| with: | |
| subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} | |
| subject-digest: ${{ steps.push.outputs.digest }} | |
| push-to-registry: true |