Skip to content

Conversation

@ricky-undeadcoders
Copy link
Contributor

This pull request refactors the Docker build workflow in .github/workflows/build.yml to improve support for multi-architecture images and streamline digest handling. The workflow now builds images for each platform separately, exports their digests, and then constructs a multi-arch manifest using those digests.

Multi-Architecture Build and Digest Export:

  • Replaces the single main job with a build-and-export-digest job that uses a matrix strategy to build Docker images for both linux/arm64 and linux/amd64 platforms, and exports their digests for later use.
  • Switches from the build-push-to-dockerhub action to the newer docker-build-push-image action.
  • We export the Docker image digest after each platform build using the docker-export-digest action.

Manifest Construction:

  • Introduces a new push-manifest job that depends on the completion of the multi-arch builds, and uses the docker-import-digests-push-manifest action to construct and upload a manifest referencing the built images for each architecture.

@ricky-undeadcoders ricky-undeadcoders requested a review from a team as a code owner October 15, 2025 23:05
Copy link
Member

@iainlane iainlane left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this! Just had a few comments which could all be due to my lack of understanding 😁

A general q: should we wait until grafana/shared-workflows#1348 is merged? As far as I can see we could use a reusable workflow since we don't do anything fancy...

uses: grafana/shared-workflows/actions/docker-import-digests-push-manifest@cd422befbbda65e0612a63627e8c8820d86bc2a6 # docker-import-digests-push-manifest/v0.1.0
with:
images: ${{ needs.build-and-export-digest.outputs.images }}
push: false
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is push: false right?

needs: build-and-export-digest
permissions:
contents: read
id-token: write
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this needed?

registries: "dockerhub"
platforms: ${{ matrix.platform }}
outputs: "type=image,push-by-digest=true,name-canonical=true,push=false"
push: false
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it right that we're never pushing? Perhaps I'm understanding the flag incorrectly

digest: ${{ steps.build.outputs.digest }}
platform: ${{ matrix.platform }}

push-manifest:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could this be conditional on whether we're pushing or not? We could skip the job on PRs, AFAIK

@ricky-undeadcoders ricky-undeadcoders deleted the rwhitaker/mulitarch-docker-builds branch October 21, 2025 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants