GitHub Action to build and push Docker images with Buildx
Find a file
CrazyMax 67a2d409c0
Some checks failed
ci / minimal (push) Waiting to run
ci / git-context (push) Waiting to run
ci / git-context-secret (push) Waiting to run
ci / path-context (push) Waiting to run
ci / example (push) Waiting to run
ci / error (push) Waiting to run
ci / error-buildx (push) Waiting to run
ci / docker-driver (push) Waiting to run
ci / export-docker (push) Waiting to run
ci / secret (push) Waiting to run
ci / secret-envs (push) Waiting to run
ci / network (push) Waiting to run
ci / shm-size (push) Waiting to run
ci / ulimit (push) Waiting to run
ci / cgroup-parent (push) Waiting to run
ci / add-hosts (push) Waiting to run
ci / no-cache-filters (push) Waiting to run
ci / attests-compat (moby/buildkit:buildx-stable-1, latest) (push) Waiting to run
ci / attests-compat (moby/buildkit:buildx-stable-1, v0.9.1) (push) Waiting to run
ci / attests-compat (moby/buildkit:v0.10.6, latest) (push) Waiting to run
ci / provenance (, /tmp/buildx-build, binary) (push) Waiting to run
ci / provenance (, type=image,name=localhost:5000/name/app:latest,push=true, image) (push) Waiting to run
ci / provenance (mode=max, /tmp/buildx-build, binary) (push) Waiting to run
ci / provenance (mode=max, type=image,name=localhost:5000/name/app:latest,push=true, image) (push) Waiting to run
ci / sbom (/tmp/buildx-build, binary) (push) Waiting to run
ci / sbom (type=image,name=localhost:5000/name/app:latest,push=true, image) (push) Waiting to run
ci / multi (multi) (push) Waiting to run
ci / multi (multi-sudo) (push) Waiting to run
ci / digest (docker, false, false) (push) Waiting to run
ci / digest (docker, false, true) (push) Waiting to run
ci / digest (docker, true, false) (push) Waiting to run
ci / digest (docker-container, false, false) (push) Waiting to run
ci / digest (docker-container, false, true) (push) Waiting to run
ci / digest (docker-container, true, false) (push) Waiting to run
ci / registry-cache (push) Waiting to run
ci / github-cache (push) Waiting to run
ci / local-cache (push) Waiting to run
ci / standalone (push) Waiting to run
ci / named-context-pin (push) Waiting to run
ci / named-context-docker (push) Waiting to run
ci / named-context-container (push) Waiting to run
ci / docker-config-malformed (push) Waiting to run
ci / proxy-docker-config (push) Waiting to run
ci / proxy-buildkitd (push) Waiting to run
ci / annotations (push) Waiting to run
ci / multi-output (push) Waiting to run
ci / load-and-push (push) Waiting to run
ci / summary-disable (push) Waiting to run
ci / summary-disable-deprecated (push) Waiting to run
ci / summary-not-supported (push) Waiting to run
ci / record-upload-disable (push) Waiting to run
ci / record-retention-days (0) (push) Waiting to run
ci / record-retention-days (2) (push) Waiting to run
ci / checks (latest) (push) Waiting to run
ci / checks (v0.14.1) (push) Waiting to run
ci / annotations-disabled (push) Waiting to run
ci / call-check (push) Waiting to run
test / test (push) Waiting to run
validate / prepare (push) Waiting to run
validate / validate (push) Blocked by required conditions
e2e / build (AWS ECR Public, AWS_SECRET_ACCESS_KEY, public.ecr.aws, public.ecr.aws/q3b5f1u4/test-docker-action, remote, AWS_ACCESS_KEY_ID) (push) Failing after 1m24s
e2e / build (AWS ECR, AWS_SECRET_ACCESS_KEY, 175142243308.dkr.ecr.us-east-2.amazonaws.com, 175142243308.dkr.ecr.us-east-2.amazonaws.com/sandbox/test-docker-action, remote, AWS_ACCESS_KEY_ID) (push) Failing after 18s
e2e / build (Artifactory, ARTIFACTORY_TOKEN, infradock.jfrog.io, infradock.jfrog.io/test-ghaction/build-push-action, remote, ARTIFACTORY_USERNAME) (push) Failing after 19s
e2e / build (Azure Container Registry, AZURE_CLIENT_SECRET, officialgithubactions.azurecr.io, officialgithubactions.azurecr.io/test-docker-action, remote, AZURE_CLIENT_ID) (push) Failing after 20s
e2e / build (Docker Hub, DOCKERHUB_TOKEN, , ghactionstest/ghactionstest, remote, DOCKERHUB_USERNAME) (push) Failing after 18s
e2e / build (GitHub, GHCR_PAT, ghcr.io, ghcr.io/docker-ghactiontest/test, remote, GHCR_USERNAME) (push) Failing after 18s
e2e / build (GitLab, GITLAB_TOKEN, registry.gitlab.com, registry.gitlab.com/test1716/test, remote, GITLAB_USERNAME) (push) Failing after 19s
e2e / build (Google Artifact Registry, GAR_JSON_KEY, us-east4-docker.pkg.dev, us-east4-docker.pkg.dev/sandbox-298914/docker-official-github-actions/test-docker-action, remote, GAR_USERNAME) (push) Failing after 19s
e2e / build (Google Container Registry, GCR_JSON_KEY, gcr.io, gcr.io/sandbox-298914/test-docker-action, remote, GCR_USERNAME) (push) Failing after 19s
e2e / build (Quay, QUAY_TOKEN, quay.io, quay.io/docker_build_team/ghactiontest, remote, QUAY_USERNAME) (push) Failing after 20s
e2e / build (distribution, Distribution, local) (push) Failing after 16s
e2e / build (harbor, Harbor, local) (push) Failing after 17s
e2e / build (nexus, Nexus, local) (push) Failing after 18s
Merge pull request #1300 from docker/dependabot/npm_and_yarn/docker/actions-toolkit-0.51.0
chore(deps): Bump @docker/actions-toolkit from 0.49.0 to 0.51.0
2025-01-15 13:50:03 +01:00
.github update bake-action to v6 2025-01-08 12:54:04 +01:00
.yarn/plugins/@yarnpkg chore: add plugin-interactive-tools yarn pkg 2024-05-06 12:01:44 +02:00
__mocks__/@actions switch to actions-toolkit implementation 2023-02-24 10:22:19 +01:00
__tests__ Revert "set repository and ghtoken attributes for gha cache type" 2024-07-17 10:47:38 +02:00
dist chore: update generated content 2025-01-15 13:44:43 +01:00
src handlebar defaultContext support for build-contexts input 2024-12-17 16:25:56 +01:00
test test: fix multi-sudo dockerfile 2024-12-17 16:12:32 +01:00
.dockerignore update to yarn 3.6.3 2024-05-06 12:01:20 +02:00
.editorconfig Move editorconfig 2020-08-11 21:05:57 +02:00
.eslintignore chore: update dev dependencies 2023-09-09 18:08:43 +02:00
.eslintrc.json chore: update dev dependencies 2024-05-15 13:41:47 +02:00
.gitattributes update to yarn 3.6.3 2024-05-06 12:01:20 +02:00
.gitignore update to yarn 3.6.3 2024-05-06 12:01:20 +02:00
.prettierignore update to yarn 3.6.3 2024-05-06 12:01:20 +02:00
.prettierrc.json Handle git sha version of buildx 2021-07-01 15:29:36 +02:00
.yarnrc.yml chore: add plugin-interactive-tools yarn pkg 2024-05-06 12:01:44 +02:00
action.yml call input to set method for evaluating build 2024-11-25 18:37:45 +01:00
codecov.yml Handle git sha version of buildx 2021-07-01 15:29:36 +02:00
dev.Dockerfile update to yarn 3.6.3 2024-05-06 12:01:20 +02:00
docker-bake.hcl update bake-action to v6 2025-01-08 12:54:04 +01:00
jest.config.ts switch to actions-toolkit implementation 2023-02-24 10:22:19 +01:00
LICENSE Rename LICENCE to LICENSE 2020-03-17 18:43:10 -07:00
package.json chore(deps): Bump @docker/actions-toolkit from 0.49.0 to 0.51.0 2025-01-15 12:07:48 +00:00
README.md readme: move login step up 2024-12-03 15:36:12 +01:00
TROUBLESHOOTING.md update troubleshooting markdown 2024-11-26 01:12:56 +01:00
tsconfig.json switch to actions-toolkit implementation 2023-02-24 10:22:19 +01:00
yarn.lock chore(deps): Bump @docker/actions-toolkit from 0.49.0 to 0.51.0 2025-01-15 12:07:48 +00:00

GitHub release GitHub marketplace CI workflow Test workflow Codecov

About

GitHub Action to build and push Docker images with Buildx with full support of the features provided by Moby BuildKit builder toolkit. This includes multi-platform build, secrets, remote cache, etc. and different builder deployment/namespacing options.

Screenshot


Usage

In the examples below we are also using 3 other actions:

  • setup-buildx action will create and boot a builder using by default the docker-container driver. This is not required but recommended using it to be able to build multi-platform images, export cache, etc.
  • setup-qemu action can be useful if you want to add emulation support with QEMU to be able to build against more platforms.
  • login action will take care to log in against a Docker registry.

Git context

By default, this action uses the Git context, so you don't need to use the actions/checkout action to check out the repository as this will be done directly by BuildKit.

The git reference will be based on the event that triggered your workflow and will result in the following context: https://github.com/<owner>/<repo>.git#<ref>.

name: ci

on:
  push:

jobs:
  docker:
    runs-on: ubuntu-latest
    steps:
      -
        name: Login to Docker Hub
        uses: docker/login-action@v3
        with:
          username: ${{ vars.DOCKERHUB_USERNAME }}
          password: ${{ secrets.DOCKERHUB_TOKEN }}
      -
        name: Set up QEMU
        uses: docker/setup-qemu-action@v3
      -
        name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3
      -
        name: Build and push
        uses: docker/build-push-action@v6
        with:
          push: true
          tags: user/app:latest

Be careful because any file mutation in the steps that precede the build step will be ignored, including processing of the .dockerignore file since the context is based on the Git reference. However, you can use the Path context using the context input alongside the actions/checkout action to remove this restriction.

Default Git context can also be provided using the Handlebars template expression {{defaultContext}}. Here we can use it to provide a subdirectory to the default Git context:

      -
        name: Build and push
        uses: docker/build-push-action@v6
        with:
          context: "{{defaultContext}}:mysubdir"
          push: true
          tags: user/app:latest

Building from the current repository automatically uses the GitHub Token, so it does not need to be passed. If you want to authenticate against another private repository, you have to use a secret named GIT_AUTH_TOKEN to be able to authenticate against it with Buildx:

      -
        name: Build and push
        uses: docker/build-push-action@v6
        with:
          push: true
          tags: user/app:latest
          secrets: |
            GIT_AUTH_TOKEN=${{ secrets.MYTOKEN }}            

Path context

name: ci

on:
  push:

jobs:
  docker:
    runs-on: ubuntu-latest
    steps:
      -
        name: Checkout
        uses: actions/checkout@v4
      -
        name: Login to Docker Hub
        uses: docker/login-action@v3
        with:
          username: ${{ vars.DOCKERHUB_USERNAME }}
          password: ${{ secrets.DOCKERHUB_TOKEN }}
      -
        name: Set up QEMU
        uses: docker/setup-qemu-action@v3
      -
        name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3
      -
        name: Build and push
        uses: docker/build-push-action@v6
        with:
          context: .
          push: true
          tags: user/app:latest

Examples

Summaries

This action generates a job summary that provides a detailed overview of the build execution. The summary shows an overview of all the steps executed during the build, including the build inputs and eventual errors.

build-push-action job summary

The summary also includes a link for downloading the build record with additional details about the build, including build stats, logs, outputs, and more. The build record can be imported to Docker Desktop for inspecting the build in greater detail.

Summaries are enabled by default, but can be disabled with the DOCKER_BUILD_SUMMARY environment variable.

For more information about summaries, refer to the documentation.

Customizing

inputs

The following inputs can be used as step.with keys:

List type is a newline-delimited string

cache-from: |
  user/app:cache
  type=local,src=path/to/dir  

CSV type is a comma-delimited string

tags: name/app:latest,name/app:1.0.0
Name Type Description
add-hosts List/CSV List of customs host-to-IP mapping (e.g., docker:10.180.0.1)
allow List/CSV List of extra privileged entitlement (e.g., network.host,security.insecure)
annotations List List of annotation to set to the image
attests List List of attestation parameters (e.g., type=sbom,generator=image)
builder String Builder instance (see setup-buildx action)
build-args List List of build-time variables
build-contexts List List of additional build contexts (e.g., name=path)
cache-from List List of external cache sources (e.g., type=local,src=path/to/dir)
cache-to List List of cache export destinations (e.g., type=local,dest=path/to/dir)
call String Set method for evaluating build (e.g., check)
cgroup-parent String Optional parent cgroup for the container used in the build
context String Build's context is the set of files located in the specified PATH or URL (default Git context)
file String Path to the Dockerfile. (default {context}/Dockerfile)
labels List List of metadata for an image
load Bool Load is a shorthand for --output=type=docker (default false)
network String Set the networking mode for the RUN instructions during build
no-cache Bool Do not use cache when building the image (default false)
no-cache-filters List/CSV Do not cache specified stages
outputs List List of output destinations (format: type=local,dest=path)
platforms List/CSV List of target platforms for build
provenance Bool/String Generate provenance attestation for the build (shorthand for --attest=type=provenance)
pull Bool Always attempt to pull all referenced images (default false)
push Bool Push is a shorthand for --output=type=registry (default false)
sbom Bool/String Generate SBOM attestation for the build (shorthand for --attest=type=sbom)
secrets List List of secrets to expose to the build (e.g., key=string, GIT_AUTH_TOKEN=mytoken)
secret-envs List/CSV List of secret env vars to expose to the build (e.g., key=envname, MY_SECRET=MY_ENV_VAR)
secret-files List List of secret files to expose to the build (e.g., key=filename, MY_SECRET=./secret.txt)
shm-size String Size of /dev/shm (e.g., 2g)
ssh List List of SSH agent socket or keys to expose to the build
tags List/CSV List of tags
target String Sets the target stage to build
ulimit List Ulimit options (e.g., nofile=1024:1024)
github-token String GitHub Token used to authenticate against a repository for Git context (default ${{ github.token }})

outputs

The following outputs are available:

Name Type Description
imageid String Image ID
digest String Image digest
metadata JSON Build result metadata

environment variables

Name Type Default Description
DOCKER_BUILD_CHECKS_ANNOTATIONS Bool true If false, GitHub annotations are not generated for build checks
DOCKER_BUILD_SUMMARY Bool true If false, build summary generation is disabled
DOCKER_BUILD_RECORD_UPLOAD Bool true If false, build record upload as GitHub artifact is disabled
DOCKER_BUILD_RECORD_RETENTION_DAYS Number Duration after which build record artifact will expire in days. Defaults to repository/org retention settings if unset or 0

Troubleshooting

See TROUBLESHOOTING.md

Contributing

Want to contribute? Awesome! You can find information about contributing to this project in the CONTRIBUTING.md