#!/usr/bin/env bash set -euo pipefail # Build (and optionally push) the CI job image from docker/Dockerfile. # Run wherever docker + registry credentials live (the runner host, or any # machine that can reach the registry). The registry/repo below MUST match # the `container.image` references in .gitea/workflows/ci.yml — the runner # pulls the image by name. # # Usage: scripts/runner-image.sh [--push] # # Why the image is baked, its two invariants, and the coordinated Node-bump # steps: development/ci.md. IMAGE_REPO="gitea.e1nsnull.de/tmu/act-ci" NODE_VERSION="$(tr -d '[:space:]' < .node-version)" if [[ ! "${NODE_VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then echo "error: .node-version must be pinned to an exact x.y.z, got '${NODE_VERSION}'." >&2 echo " setup-node resolves floats like '26' to the latest patch at runtime," >&2 echo " which silently busts the tool-cache entry baked into the image." >&2 exit 1 fi IMAGE="${IMAGE_REPO}:${NODE_VERSION}" # --pull: refresh the act base layer so the derivative does not float on an # aging default image forever (layer dedup keeps this cheap). docker build --pull --build-arg "NODE_VERSION=${NODE_VERSION}" -t "${IMAGE}" -f docker/Dockerfile . if [[ "${1:-}" == "--push" ]]; then docker push "${IMAGE}" fi echo "built ${IMAGE}" echo "reminder: bump container.image in .gitea/workflows/ci.yml to this tag"