From f028216d390e04977d200048a2c38499479c6a4b Mon Sep 17 00:00:00 2001 From: torrid-fish Date: Thu, 16 Jul 2026 08:48:52 +0000 Subject: [PATCH] ci(cd): build multi-arch images (amd64 + arm64) --- .github/workflows/cd.yml | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml index b3c7c52..743da54 100644 --- a/.github/workflows/cd.yml +++ b/.github/workflows/cd.yml @@ -77,11 +77,13 @@ jobs: type=semver,pattern={{major}}.{{minor}} type=raw,value=stable,enable=${{ startsWith(github.ref, 'refs/tags/v') }} - - name: Build image + - name: Build amd64 image for smoke test uses: docker/build-push-action@v7 with: context: . file: ./Dockerfile + # Smoke test runs on the runner, so this stage stays native amd64: + # buildx cannot `load` a multi-platform result into the daemon. platforms: linux/amd64 push: false load: true @@ -112,5 +114,19 @@ jobs: docker exec "$container" python -c \ "import json, urllib.request; request=urllib.request.Request('http://127.0.0.1:8000/api/MarkAccent/', data=json.dumps({'text':'東京'}).encode(), headers={'Content-Type':'application/json'}); response=json.load(urllib.request.urlopen(request, timeout=30)); assert response['status'] == 200 and response['result']" - - name: Push smoke-tested image - run: docker push --all-tags "${REGISTRY}/${IMAGE_NAME}" + - name: Push smoke-tested image (amd64 + arm64) + uses: docker/build-push-action@v7 + with: + context: . + file: ./Dockerfile + # arm64 so images run natively on the arm64 (Oracle Ampere) deploy + # host. amd64 layers come from the cache the smoke build just wrote, + # so only the arm64 half is rebuilt (under QEMU). + platforms: linux/amd64,linux/arm64 + push: true + provenance: true + sbom: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + cache-from: type=gha + cache-to: type=gha,mode=max