name: Build HugoBlox devcontainer image on: push: branches: [main] paths: - ".devcontainer/base.Dockerfile" - ".github/workflows/devcontainer-image.yml" workflow_dispatch: inputs: hugo_versions: description: "Comma-separated Hugo versions to build (e.g. 0.152.2,0.154.0)" required: false env: IMAGE_NAME: ghcr.io/hugoblox/hugo-blox-dev # Hugo >= 0.161.1 required: 0.161.0 introduced the Node permission # sandbox without an allowChildProcess field, blocking spawns under # tailwindcss (e.g. @parcel/watcher → detect-libc → getconf on Linux). DEFAULT_HUGO_VERSION: 0.161.1 NODE_VERSION: 22 PNPM_VERSION: 10.14.0 jobs: prepare-matrix: runs-on: ubuntu-latest outputs: versions: ${{ steps.versions.outputs.matrix }} steps: - name: Select Hugo versions id: versions env: VERSIONS: ${{ github.event.inputs.hugo_versions || env.DEFAULT_HUGO_VERSION }} run: | MATRIX=$(python - <<'PY' import os, json versions = [v.strip() for v in os.environ["VERSIONS"].split(",") if v.strip()] print(json.dumps(versions)) PY ) echo "matrix=${MATRIX}" >> "$GITHUB_OUTPUT" build-and-push: needs: prepare-matrix runs-on: ubuntu-latest permissions: contents: read packages: write strategy: fail-fast: false matrix: hugo: ${{ fromJson(needs.prepare-matrix.outputs.versions) }} steps: - name: Checkout uses: actions/checkout@v6 - name: Log in to GHCR uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Compute tags id: tags env: HUGO_VERSION: ${{ matrix.hugo }} run: | TAGS="${IMAGE_NAME}:hugo${HUGO_VERSION}" if [ "${HUGO_VERSION}" = "${DEFAULT_HUGO_VERSION}" ]; then TAGS="${TAGS}\n${IMAGE_NAME}:latest" fi { echo "list<> "$GITHUB_OUTPUT" - name: Build and push image uses: docker/build-push-action@v7 with: context: . file: .devcontainer/base.Dockerfile push: true build-args: | HUGO_VERSION=${{ matrix.hugo }} NODE_VERSION=${{ env.NODE_VERSION }} PNPM_VERSION=${{ env.PNPM_VERSION }} tags: ${{ steps.tags.outputs.list }}