使用 GitHub Actions 驗證構建配置

構建檢查允許您在不實際執行構建的情況下驗證您的 docker build 配置。

使用 docker/build-push-action 執行檢查

要在 GitHub Actions 工作流中使用 build-push-action 執行構建檢查,請將 call 輸入引數設定為 check。設定此項後,如果您的構建配置檢測到任何檢查警告,工作流將失敗。

name: ci

on:
  push:

jobs:
  docker:
    runs-on: ubuntu-latest
    steps:
      - name: Login to Docker Hub
        uses: docker/login-action@v3
        with:
          username: ${{ secrets.DOCKERHUB_USERNAME }}
          password: ${{ secrets.DOCKERHUB_TOKEN }}
      
      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3

      - name: Validate build configuration
        uses: docker/build-push-action@v6
        with:
          call: check

      - name: Build and push
        uses: docker/build-push-action@v6
        with:
          push: true
          tags: user/app:latest

使用 docker/bake-action 執行檢查

如果您使用 Bake 和 docker/bake-action 來執行構建,則無需在 GitHub Actions 工作流配置中指定任何特殊輸入。相反,請定義一個呼叫 check 方法的 Bake 目標,並在您的 CI 中呼叫該目標。

target "build" {
  dockerfile = "Dockerfile"
  args = {
    FOO = "bar"
  }
}
target "validate-build" {
  inherits = ["build"]
  call = "check"
}
name: ci

on:
  push:

env:
  IMAGE_NAME: user/app

jobs:
  docker:
    runs-on: ubuntu-latest
    steps:
      - name: Login to Docker Hub
        uses: docker/login-action@v3
        with:
          username: ${{ vars.DOCKERHUB_USERNAME }}
          password: ${{ secrets.DOCKERHUB_TOKEN }}

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3

      - name: Validate build configuration
        uses: docker/bake-action@v6
        with:
          targets: validate-build

      - name: Build
        uses: docker/bake-action@v6
        with:
          targets: build
          push: true