# Container

- Object ID: `em:automation:sha256:3a90a6127614f1a6487a4ae37ab09608f1b6486e9b32716f9be2c7ed831b9e44`
- Kind: `automation`
- Repository path: [`.github/workflows/container.yml`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/.github/workflows/container.yml)
- Content digest: `772d8067eac4691255f3bb2b3279093ff1e87d7bb00c2b4646e2720ee60b6598`

**Also filed under:** [Agent Operations](https://epistemedia.org/topics/agent-operations/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/)

## Source content

name: publish-container

on:
  workflow_dispatch:
    inputs:
      tag:
        description: Existing accepted release tag to build and publish.
        required: true
        type: string
      confirm_publish:
        description: Publish the image to GHCR.
        required: true
        default: false
        type: boolean

permissions: {}

jobs:
  image:
    if: github.ref == 'refs/heads/main' && inputs.confirm_publish
    environment: ghcr
    permissions:
      contents: read
      packages: write
    runs-on: ubuntu-latest
    timeout-minutes: 25
    steps:
      - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
        with:
          ref: ${{ inputs.tag }}
          fetch-depth: 0
          persist-credentials: false
      - name: Verify accepted release tag
        id: release
        env:
          RELEASE_TAG: ${{ inputs.tag }}
        run: |
          if [[ ! "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
            echo 'Release tag must have the exact form vMAJOR.MINOR.PATCH.'
            exit 1
          fi
          RELEASE_SHA="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")"
          test "$(git rev-parse HEAD)" = "$RELEASE_SHA"
          git fetch origin main --no-tags
          git merge-base --is-ancestor "$RELEASE_SHA" origin/main
          SOURCE_EPOCH="$(git show -s --format=%ct "$RELEASE_SHA")"
          test -n "$SOURCE_EPOCH"
          echo "sha=$RELEASE_SHA" >> "$GITHUB_OUTPUT"
          echo "short_sha=${RELEASE_SHA:0:12}" >> "$GITHUB_OUTPUT"
          echo "source_epoch=$SOURCE_EPOCH" >> "$GITHUB_OUTPUT"
      - uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
      - uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}
      - uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
        id: meta
        with:
          images: ghcr.io/yoheinakajima/epistemedia
          tags: |
            type=raw,value=${{ inputs.tag }}
            type=raw,value=sha-${{ steps.release.outputs.short_sha }}
      - uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
        with:
          context: .
          build-args: |
            EPISTEMEDIA_ACCEPTED_COMMIT=${{ steps.release.outputs.sha }}
            SOURCE_DATE_EPOCH=${{ steps.release.outputs.source_epoch }}
          push: true
          tags: ${{ steps.meta.outputs.tags }}
          labels: ${{ steps.meta.outputs.labels }}
          provenance: mode=max
          sbom: true
