-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathjustfile
More file actions
191 lines (160 loc) · 6.37 KB
/
Copy pathjustfile
File metadata and controls
191 lines (160 loc) · 6.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
version := ''
image := 'ghcr.io/linkerd/dev'
# Auto-detect latest git version if version is 'latest-git-tag'
_version := if version == 'latest-git-tag' {
shell('which git > /dev/null || (echo >&2 "$1error$2: git not available" && exit 1) && git --git-dir="$3/.git" --work-tree="$3" tag -l --sort=-version:refname "v*" | head -n 1', style('error'), NORMAL, justfile_directory())
} else {
version
}
_tag := if _version != '' { "--tag=" + image + ':' + _version } else { "" }
k3s-image := 'docker.io/rancher/k3s'
dry_run := 'false'
# Detect docker_bin if not specified: try docker first, then podman
docker_bin := shell('which docker 2> /dev/null || which podman 2> /dev/null || (echo >&2 "$1error$2: neither docker nor podman found" && exit 1)', style('error'), NORMAL)
# Extract basename of docker_bin to identify implementation
_docker_bin_name := file_name(docker_bin)
# Auto-detect if podman is in remote mode (unless explicitly overridden)
podman_remote := if _docker_bin_name == 'podman' {
shell('if $1 info 2>/dev/null | grep -q "remoteSocket"; then echo "true"; else echo "false"; fi', docker_bin)
} else {
'false'
}
# pull policy
_pull_policy := if _docker_bin_name == 'podman' {
'=never'
} else {
''
}
targets := 'go rust rust-musl tools devcontainer'
load := 'false'
push := 'false'
# Platforms to build, as a comma-delimited list of os/arch pairs. Published
# images must support both architectures; local builds default to the host
# platform so that iterating on the Dockerfile stays fast (and because
# multi-platform images cannot be loaded into the local image store).
# See https://github.com/docker/buildx/issues/59
docker_arch := if push == 'true' { 'linux/amd64,linux/arm64' } else { '' }
_multi_arch := if docker_arch =~ ',' { 'true' } else { 'false' }
# Remote mode cannot use the --output flag
output := if podman_remote == 'true' {
''
} else if push == 'true' {
'--output=type=registry'
} else if load == 'true' {
'--output=type=docker'
} else {
'--output=type=image'
}
export DOCKER_PROGRESS := env_var_or_default('DOCKER_PROGRESS', 'auto')
all: sync-k3s-images build
build *args='': && _list-if-load
#!/usr/bin/env bash
set -euo pipefail
for tgt in {{ targets }} ; do
just output='{{ output }}' \
image='{{ image }}' \
version='{{ _version }}' \
docker_arch='{{ docker_arch }}' \
dry_run='{{ dry_run }}' \
docker_bin='{{ docker_bin }}' \
podman_remote='{{ podman_remote }}' \
_target "$tgt" \
{{ args }}
done
_list-if-load:
#!/usr/bin/env bash
set -euo pipefail
if [ '{{ load }}' = 'true' ] ; then
just image='{{ image }}' \
targets='{{ targets }}' \
version='{{ _version }}' \
list
fi
list:
#!/usr/bin/env bash
set -euo pipefail
if [ -z '{{ _version }}' ]; then
echo "Usage: just version=<version> list" >&2
exit 64
fi
for tgt in {{ targets }} ; do
if [ "$tgt" == "devcontainer" ]; then
cmd="{{ docker_bin }} image ls {{ image }}:{{ _version }} | sed 1d"
else
cmd="{{ docker_bin }} image ls {{ image }}:{{ _version }}-$tgt | sed 1d"
fi
echo "{{ style('error') }}$cmd{{ NORMAL }}"
if [ "{{ dry_run }}" = "true" ]; then
continue
fi
eval "$cmd"
done
# Fetch the latest version of k3s images and record their tags and digests.
sync-k3s-images:
#!/usr/bin/env bash
set -euo pipefail
CHANNELS=$(just minimum-k8s='{{ minimum-k8s }}' _k3s-channels)
DIGESTS=$(for tag in $(echo "$CHANNELS" | jq -r 'to_entries | .[].value' | sort -u) ; do
jo key="$tag" value="$(just k3s-image='{{ k3s-image }}' _k3s-inspect "${tag}" | jq -r '.Digest')"
done | jq -cs 'from_entries')
MISSING_CHANNELS=$(echo "$DIGESTS" | jq -r 'to_entries | map(select(.value == null) | .key) | .[]')
if [[ -n "$MISSING_CHANNELS" ]]; then
echo "Error: Digests could not be discovered for the following channels:" >&2
echo "$MISSING_CHANNELS" | while IFS= read -r channel; do echo "- $channel"; done >&2
exit 11
fi
jo name='{{ k3s-image }}' channels="$CHANNELS" digests="$DIGESTS" \
| jq . > k3s-images.json
jq . k3s-images.json
minimum-k8s := '31'
update-versions:
go run ./update-versions.go --in-place
# Inspect a k3s image by tag
_k3s-inspect tag:
skopeo inspect 'docker://{{ k3s-image }}:{{ tag }}'
# Fetch the latest tag for non-EOL channels.
_k3s-channels:
#!/usr/bin/env bash
set -euo pipefail
scurl 'https://update.k3s.io/v1-release/channels' \
| jq -cr '[.data[]
| select(.type == "channel")
| select(.id | test("^(.*-)?testing") | not)
| (.latest | sub("\\+"; "-")) as $tag
| ($tag | capture("^v1\\.(?<v>\\d+)\\.\\d+-.*") | .v | tonumber) as $version
| select($version >= {{ minimum-k8s }})
| {key:.id, value:$tag}
] | from_entries'
_target target='' *args='':
@just \
output='{{ output }}' \
image='{{ image }}' \
version='{{ _version }}' \
docker_arch='{{ docker_arch }}' \
dry_run='{{ dry_run }}' \
docker_bin='{{ docker_bin }}' \
podman_remote='{{ podman_remote }}' \
_build --target='{{ target }}' \
{{ if _version == '' { '' } else { '--tag=' + image + ':' + _version + if target == 'devcontainer' { '' } else { '-' + target } } }} \
{{ args }}
# Build the devcontainer image
_build *args='':
#!/usr/bin/env bash
set -euo pipefail
if [ '{{ _multi_arch }}' = 'true' ] && [[ '{{ output }}' == *type=docker* ]]; then
echo >&2 "{{ style('error') }}error{{ NORMAL }}: multi-platform images cannot be loaded into the local image store."
echo >&2 "Build a single platform, e.g. docker_arch=linux/arm64, or use push=true."
exit 64
fi
cmd="{{ docker_bin }} buildx build . {{ _tag }} --pull{{ _pull_policy }} \
--progress='{{ DOCKER_PROGRESS }}' \
{{ output }} \
{{ if docker_arch != '' { '--platform=' + docker_arch } else { '' } }} \
{{ args }}"
echo "{{ style('error') }}$cmd{{ NORMAL }}"
if [ "{{ dry_run }}" = "true" ]; then
exit 0
fi
eval "$cmd"
md-lint *patterns="'**/*.md' '!repos/**'":
@bin/just-md lint {{ patterns }}