Deploy workflow: commit-id image tags, guarded deploy.sh, opt-in prune

- Makefile builds from 'git archive HEAD' (stale-remote-HEAD impossible):
  tags registry.tanshu.com/mozimo:<short-commit> + :main; build-check target
  verifies both architectures without pushing
- deploy.sh: refuses dirty tracked tree / HEAD != origin/main (--force to
  bypass), ff-only pull, passes the commit as image_tag to ansible,
  --prune flag for opt-in image cleanup
- ansible: docker_image uses image_tag extra-var (falls back to tag),
  prune task keeps the 3 newest mozimo images, mozimo-repo only
This commit is contained in:
2026-09-06 13:21:16 +05:30
parent 424a2b016a
commit 134f0b0a7a
4 changed files with 73 additions and 16 deletions
+16 -5
View File
@@ -1,8 +1,19 @@
COMMIT ?= $(shell git rev-parse --short HEAD)
.PHONY: build-production
build-production: ## Build the production docker image.
@docker buildx build \
build-production: ## Multi-arch build from HEAD; tags registry.tanshu.com/mozimo:<commit> + :main
@git archive --format=tar HEAD | docker buildx build \
--platform linux/amd64,linux/arm64 \
--tag registry.tanshu.com/mozimo:staging \
$(if $(TAG),--tag registry.tanshu.com/mozimo:$(TAG)) \
--tag registry.tanshu.com/mozimo:$(COMMIT) \
--tag registry.tanshu.com/mozimo:main \
--push \
git@git.tanshu.com:tanshu/mozimo.in.git
-
.PHONY: build-check
build-check: ## Multi-arch compile check from HEAD, nothing pushed
@git archive --format=tar HEAD | docker buildx build \
--platform linux/amd64,linux/arm64 \
--tag mozimo:check \
--pull \
--progress=plain \
-