name: Build and Push Docker Image on: workflow_dispatch: push: branches: - main paths: - 'app.py' - 'dockerfile' - 'requirements.txt' - 'docker-compose.yml' jobs: build-and-push: runs-on: ubuntu-latest permissions: contents: read packages: write steps: - name: Checkout repository uses: actions/checkout@v4 - name: Prepare Registry Environment id: prep run: | if [[ "${{ github.server_url }}" == *"github.com"* ]]; then echo "REGISTRY=ghcr.io" >> $GITHUB_ENV else # Strip protocol (http/https) to get just the hostname:port CLEAN_HOST=$(echo "${{ github.server_url }}" | sed -e 's|^[^/]*//||' -e 's|/.*$||') echo "REGISTRY=$CLEAN_HOST" >> $GITHUB_ENV fi IMAGE_NAME=$(echo "${{ github.repository }}" | tr '[:upper:]' '[:lower:]') echo "IMAGE_NAME=$IMAGE_NAME" >> $GITHUB_ENV - name: Log in to Container Registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} # UPDATED STEP: Allow HTTP/Insecure registry - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: buildkitd-config-inline: | [registry."${{ env.REGISTRY }}"] http = true insecure = true - name: Build and push multi-arch Docker image uses: docker/build-push-action@v5 with: context: . push: true platforms: linux/amd64,linux/arm64 tags: | ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} cache-from: type=gha cache-to: type=gha,mode=max