Skip to content

Commit

Permalink
ci: add container build workflow for fork
Browse files Browse the repository at this point in the history
We cannot depend on the upstream `informalsystems/hermes` repo for CI
deployments, because we need the forked Hermes code for compatiblity
with Penumbra chains. Added a new workflow that will publish as
`ghcr.io/penumbra-zone/hermes`, and removed the informalsystems one.
  • Loading branch information
conorsch committed Apr 12, 2024
1 parent f760c7e commit f0bb9e8
Show file tree
Hide file tree
Showing 5 changed files with 112 additions and 147 deletions.
17 changes: 7 additions & 10 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,10 +1,7 @@
/.changelog/
/.git/
/.gitignore
/.github
/ci/
/docs/
/e2e/
/guide/
/scripts/
/target/
# ignore everything
**
# selectively un-ignore rust files
!crates/
!tools/
!Cargo.*
!.cargo/config.toml
60 changes: 60 additions & 0 deletions .github/workflows/container.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
---
name: Build container image
on:
workflow_call:
workflow_dispatch:
# Support triggering builds from penumbra-zone/penumbra CI.
repository_dispatch:
types:
- container-build
push:
branches:
- main
tags:
- '**'
jobs:
hermes:
runs-on: buildjet-16vcpu-ubuntu-2004
permissions:
contents: read
packages: write

steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Log in to the Docker Hub container registry (for pulls)
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Log in to the GitHub container registry (for pushes)
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/penumbra-zone/hermes

# Grab the tag from the Cargo.toml file, so we can use it as a tag on the container image.
- name: Look up Penumbra dep version
id: penumbra_version
run: echo "PENUMBRA_VERSION=$(grep -P '^penumbra-proto ' Cargo.toml | grep -oP 'v[\d.]+')" >> "$GITHUB_OUTPUT"

- name: Build and push Docker image
uses: docker/build-push-action@v5
with:
context: .
platforms: linux/amd64
file: ci/release/Containerfile
push: true
# We include a tag with the associated Penumbra, e.g. `penumbra-v0.61.0`.
# This is important to maintain compatibility with a long-running testnet.
tags: ${{ steps.meta.outputs.tags }},ghcr.io/penumbra-zone/hermes:penumbra-${{ steps.penumbra_version.outputs.PENUMBRA_VERSION }}
labels: ${{ steps.meta.outputs.labels }}
130 changes: 0 additions & 130 deletions .github/workflows/docker.yml

This file was deleted.

14 changes: 7 additions & 7 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -41,17 +41,11 @@ astria-sequencer-client = { git = "https://github.com/astriaorg/astria", rev = "
"http",
] }

# Penumbra dependencies
# Penumbra dependencies.
penumbra-asset = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-custody = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-fee = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-ibc = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
# Astria is on v0.69.1 right now
penumbra-ibc-astria = { git = "https://github.com/penumbra-zone/penumbra", package = "penumbra-ibc", tag = "v0.69.1" }
penumbra-proto-astria = { git = "https://github.com/penumbra-zone/penumbra", package = "penumbra-proto", tag = "v0.69.1", features = [
"box-grpc",
"rpc",
] }
penumbra-keys = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-proto = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0", features = [
"box-grpc",
Expand All @@ -60,6 +54,12 @@ penumbra-proto = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.
penumbra-transaction = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-wallet = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
penumbra-view = { git = "https://github.com/penumbra-zone/penumbra", tag = "v0.71.0" }
# Penumbra dependencies, specifically for Astria support. Renamespaced, to avoid conflicts with Penumbra support.
penumbra-ibc-astria = { git = "https://github.com/penumbra-zone/penumbra", package = "penumbra-ibc", tag = "v0.69.1" }
penumbra-proto-astria = { git = "https://github.com/penumbra-zone/penumbra", package = "penumbra-proto", tag = "v0.69.1", features = [
"box-grpc",
"rpc",
] }

# Other dependencies
abscissa_core = "=0.6.0"
Expand Down
38 changes: 38 additions & 0 deletions ci/release/Containerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
FROM docker.io/rust:1-bookworm AS builder
COPY . /usr/src/hermes
WORKDIR /usr/src/hermes

# Install build dependencies. These packages should match what's recommended on
# https://guide.penumbra.zone/main/pcli/install.html
RUN apt-get update && apt-get install -y --no-install-recommends \
git-lfs \
build-essential \
pkg-config \
libssl-dev \
clang \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*

# In the future we may want to support building against multiple versions of Penumbra,
# so we can get early warning about breaking changes in CI. Not hooking that up now:
# we'll use the Penumbra versions specified in the `Cargo.toml` workspace settings.
# ARG PENUMBRA_VERSION="v0.71.0"
# Set the desired PENUMBRA_VERSION in the Cargo.toml file prior to building.
# This regex intentionally ignores the renamespaced Astria deps.
# RUN sed -i -e "/^penumbra-.*-astria/! s/^\(penumbra-.*\)\(tag = \".*\"\)\(.*\)$/\1branch = \"${PENUMBRA_VERSION}\"\3/" Cargo.toml && cat Cargo.toml
RUN cargo build --release

# Runtime container, with binary and normal user account.
FROM docker.io/debian:bookworm-slim
LABEL maintainer="[email protected]"

COPY --from=builder /usr/src/hermes/target/release/hermes /usr/bin/hermes
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*

RUN groupadd --gid 1000 hermes \
&& useradd -m -d /home/hermes -g 1000 -u 1000 hermes
WORKDIR /home/hermes
USER hermes
ENTRYPOINT ["/usr/bin/hermes"]

0 comments on commit f0bb9e8

Please sign in to comment.