Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
146 changes: 120 additions & 26 deletions .github/workflows/build-envoy-image-ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,6 @@ on:
permissions:
# To be able to access the repository with `actions/checkout`
contents: read
# Required to generate OIDC tokens for `sigstore/cosign-installer` authentication
id-token: write

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.event.after }}
Expand All @@ -16,8 +14,15 @@ concurrency:
jobs:
build-and-push-prs:
name: Build and push multi-arch images
permissions:
contents: read
# Required by the Quay OIDC token exchange and keyless cosign signing.
id-token: write
# Pins the OIDC token subject to
# repo:cilium/proxy:environment:publish-ci-images, which is the identity
# federated with the Quay robot account.
environment:
name: ci-build
Comment thread
aanm marked this conversation as resolved.
name: publish-ci-images
deployment: false
timeout-minutes: 360
runs-on: ${{ vars.PROXY_BUILD_GITHUB_RUNNER }}
Expand All @@ -32,20 +37,31 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Install skopeo
run: |
sudo apt-get update
sudo apt-get install -y skopeo

- name: Install Cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2

- name: Install Bom
shell: bash
env:
# renovate: datasource=github-releases depName=kubernetes-sigs/bom
BOM_VERSION: v0.7.1
run: |
curl -L https://github.com/kubernetes-sigs/bom/releases/download/${{ env.BOM_VERSION }}/bom-amd64-linux -o bom
sudo mv ./bom /usr/local/bin/bom
sudo chmod +x /usr/local/bin/bom

- name: Cache Docker layers
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: /tmp/buildx-cache
key: docker-cache-${{ github.head_ref }}
restore-keys: docker-cache-main

- name: Login to quay.io
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: quay.io
username: ${{ secrets.QUAY_ENVOY_USERNAME_DEV }}
password: ${{ secrets.QUAY_ENVOY_PASSWORD_DEV }}

- name: Checkout PR
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down Expand Up @@ -77,7 +93,7 @@ jobs:
echo exists="false" >> $GITHUB_OUTPUT
fi

- name: PR Multi-arch build & push of Builder image (dev)
- name: PR Multi-arch build of Builder image (dev)
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
id: docker_build_builder_ci
Expand All @@ -86,8 +102,61 @@ jobs:
context: .
file: ./Dockerfile.builder
platforms: linux/amd64,linux/arm64
push: true
push: false
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
outputs: type=oci,dest=${{ runner.temp }}/builder-dev.tar

# Quay's registry endpoint only accepts credentials or a JWT signed by
# Quay itself, so the GitHub OIDC token cannot be used as the registry
# password directly. Trade it for a short lived robot token first.
#
# Because the job references an environment, the subject of the token is
# repo:cilium@21054566/proxy@155294575:environment:publish-ci-images, the
# immutable form that carries the owner and repository ids. That is the
# identity federated with the robot account on the Quay side, so renaming
# the environment breaks the login.
#
# Quay gives the token one hour and the builds below take hours, so every
# artifact gets its own token once its build finishes. Nothing before the
# first push needs Quay auth: the builder tag lookup and the BUILDER_BASE
# and ARCHIVE_IMAGE pulls all read public repositories.
- name: Get a quay.io robot token via OIDC for the Builder image (dev)
id: token-builder-dev
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
env:
ROBOT: ${{ vars.QUAY_ROBOT_CI }}
run: |
oidc_token="$(curl -sSf --retry 3 --retry-all-errors \
-H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=quay.io" \
| jq -er '.value')"
echo "::add-mask::${oidc_token}"

# Pass the credentials on stdin so that the OIDC token is not visible
# in the process list of the runner.
robot_token="$(printf 'user = "%s:%s"\n' "${ROBOT}" "${oidc_token}" \
| curl -sSf --retry 3 --retry-all-errors -K - \
"https://quay.io/oauth2/federation/robot/token" \
| jq -er '.token')"
echo "::add-mask::${robot_token}"

echo "token=${robot_token}" >> "$GITHUB_OUTPUT"

- name: Login to quay.io for the Builder image (dev)
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
with:
registry: quay.io
username: ${{ vars.QUAY_ROBOT_CI }}
password: ${{ steps.token-builder-dev.outputs.token }}

- name: PR Push of Builder image (dev)
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
run: |
skopeo copy --multi-arch all \
"oci-archive:${{ runner.temp }}/builder-dev.tar" \
docker://quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
rm -f "${{ runner.temp }}/builder-dev.tar"

- name: CI Builder Image Digest
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
Expand All @@ -96,7 +165,7 @@ jobs:
echo "Digests:"
echo "quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}@${{ steps.docker_build_builder_ci.outputs.digest }}"

- name: PR Multi-arch build & push of cilium-envoy
- name: PR Multi-arch build of cilium-envoy
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
id: docker_build_ci
with:
Expand All @@ -110,25 +179,50 @@ jobs:
BAZEL_BUILD_OPTS=--remote_upload_local_results=false
cache-from: type=local,src=/tmp/buildx-cache
cache-to: type=local,dest=/tmp/buildx-cache,mode=max
push: true
push: false
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-dev:${{ github.event.pull_request.head.sha }}
outputs: type=oci,dest=${{ runner.temp }}/cilium-envoy-dev.tar

- name: Install Cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
# A token of its own for this push; see the token exchange above. The
# cosign and SBOM steps below write to quay.io with it too.
- name: Get a quay.io robot token via OIDC for cilium-envoy
id: token-cilium-envoy-dev
env:
ROBOT: ${{ vars.QUAY_ROBOT_CI }}
run: |
oidc_token="$(curl -sSf --retry 3 --retry-all-errors \
-H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=quay.io" \
| jq -er '.value')"
echo "::add-mask::${oidc_token}"

- name: Sign Container Image
# Pass the credentials on stdin so that the OIDC token is not visible
# in the process list of the runner.
robot_token="$(printf 'user = "%s:%s"\n' "${ROBOT}" "${oidc_token}" \
| curl -sSf --retry 3 --retry-all-errors -K - \
"https://quay.io/oauth2/federation/robot/token" \
| jq -er '.token')"
echo "::add-mask::${robot_token}"

echo "token=${robot_token}" >> "$GITHUB_OUTPUT"

- name: Login to quay.io for cilium-envoy
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: quay.io
username: ${{ vars.QUAY_ROBOT_CI }}
password: ${{ steps.token-cilium-envoy-dev.outputs.token }}

- name: PR Push of cilium-envoy
run: |
cosign sign -y quay.io/${{ github.repository_owner }}/cilium-envoy-dev@${{ steps.docker_build_ci.outputs.digest }}
skopeo copy --multi-arch all \
"oci-archive:${{ runner.temp }}/cilium-envoy-dev.tar" \
docker://quay.io/${{ github.repository_owner }}/cilium-envoy-dev:${{ github.event.pull_request.head.sha }}
rm -f "${{ runner.temp }}/cilium-envoy-dev.tar"

- name: Install Bom
shell: bash
env:
# renovate: datasource=github-releases depName=kubernetes-sigs/bom
BOM_VERSION: v0.7.1
- name: Sign Container Image
run: |
curl -L https://github.com/kubernetes-sigs/bom/releases/download/${{ env.BOM_VERSION }}/bom-amd64-linux -o bom
sudo mv ./bom /usr/local/bin/bom
sudo chmod +x /usr/local/bin/bom
cosign sign -y quay.io/${{ github.repository_owner }}/cilium-envoy-dev@${{ steps.docker_build_ci.outputs.digest }}

- name: Generate SBOM
shell: bash
Expand Down
Loading
Loading