Chapter 9: GitHub Actions Hands-On
9.5 Build and push an image (GHCR sketch)
Goal from Chapter 8: on main, build and push badge-api:<sha>.
# sketch — adjust package name / visibility for your account
env:
IMAGE: ghcr.io/${{ github.repository_owner }}/badge-api
jobs:
docker:
needs: test
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v6
with:
context: .
push: true
tags: |
${{ env.IMAGE }}:${{ github.sha }}
${{ env.IMAGE }}:latest
Docker Hub variant: store DOCKERHUB_USERNAME and DOCKERHUB_TOKEN as Actions secrets; login to docker.io; never paste the token into YAML.
What you see: Packages (GHCR) or Docker Hub shows a new tag equal to the commit SHA. Your notes should record that SHA for staging.
Ravindra Bagale's Tip
latest convenience sathi thevla tari SHA tag deploy kara. Rollback = previous SHA. Interview madhe he sanga. Bilkul visru naka!