Python basic images #6562
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Python basic images | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| release_tag: | |
| description: 'Tag for the images (e.g.: "latest" or "beta")' | |
| required: true | |
| rebuild_images: | |
| description: "Rebuilds images even if the cache state matches the current state." | |
| required: false | |
| type: boolean | |
| trigger_templates_pr: | |
| description: "When set to true, always triggers the workflow on actor-templates." | |
| required: false | |
| type: boolean | |
| repository_dispatch: | |
| types: [build-python-images] | |
| pull_request: | |
| paths: | |
| - "python/**" | |
| - ".github/workflows/release-python.yaml" | |
| - ".github/actions/version-matrix/**" | |
| - ".github/scripts/prepare-python-image-tags.js" | |
| - "Makefile" | |
| schedule: | |
| - cron: 0 */2 * * * | |
| env: | |
| RELEASE_TAG: ${{ github.event.inputs.release_tag || github.event.client_payload.release_tag }} | |
| SKIP_CACHE_CHECK: ${{ github.event_name == 'pull_request' || github.event.inputs.rebuild_images == 'true' }} | |
| jobs: | |
| matrix: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| matrix: ${{ steps.set-matrix.outputs.matrix }} | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }} | |
| fetch-depth: 0 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version-file: .github/actions/version-matrix/package.json | |
| cache: yarn | |
| cache-dependency-path: .github/actions/version-matrix/yarn.lock | |
| - run: yarn | |
| working-directory: ./.github/actions/version-matrix | |
| - name: Generate matrix | |
| id: set-matrix | |
| run: echo "matrix=$(yarn python:normal)" >> $GITHUB_OUTPUT | |
| working-directory: ./.github/actions/version-matrix | |
| - name: Print matrix | |
| run: | | |
| echo '${{ steps.set-matrix.outputs.matrix }}' | jq -r '.include[] | "python-version=\(.["python-version"])"' | |
| echo "" | |
| echo "Raw matrix:" | |
| echo "" | |
| echo '${{ steps.set-matrix.outputs.matrix }}' | jq -e | |
| - name: Commit updated matrix | |
| id: commit | |
| if: github.event_name != 'pull_request' | |
| uses: apify/actions/signed-commit@v1.2.0 | |
| with: | |
| message: "chore(docker): update ${{ env.RELEASE_TAG || 'latest' }} python:normal cache" | |
| add: ./.github/actions/version-matrix/data/*.json | |
| retries: 5 | |
| pull: '--rebase --autostash' | |
| github-token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }} | |
| - name: Trigger workflow on actor-templates | |
| if: (steps.commit.outputs.committed == 'true' || github.event.inputs.trigger_templates_pr == 'true') && steps.set-matrix.outputs.latest-runtime-version != '' | |
| uses: peter-evans/repository-dispatch@v4 | |
| with: | |
| token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }} | |
| repository: apify/actor-templates | |
| event-type: update-templates | |
| client-payload: |- | |
| { | |
| "base_image": "apify/actor-python", | |
| "default_runtime_version": "${{ steps.set-matrix.outputs.latest-runtime-version }}" | |
| } | |
| # Build master images that are not dependent on existing builds. | |
| build-main: | |
| needs: [matrix] | |
| runs-on: ubuntu-latest | |
| if: ${{ toJson(fromJson(needs.matrix.outputs.matrix).include) != '[]' }} | |
| strategy: | |
| fail-fast: false | |
| matrix: ${{ fromJson(needs.matrix.outputs.matrix) }} | |
| name: "py: ${{ matrix.python-version }}" | |
| steps: | |
| - name: Set default inputs if event is pull request | |
| if: github.event_name == 'pull_request' | |
| run: | | |
| if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG=CI_TEST" >> $GITHUB_ENV; fi | |
| - name: Set default inputs if event is schedule | |
| if: github.event_name == 'schedule' | |
| run: | | |
| if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG=latest" >> $GITHUB_ENV; fi | |
| - name: Check if inputs are set correctly | |
| run: | | |
| if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG input is empty!" >&2; exit 1; fi | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Prepare image tags | |
| id: prepare-tags | |
| uses: actions/github-script@v8 | |
| env: | |
| CURRENT_PYTHON: ${{ matrix.python-version }} | |
| LATEST_PYTHON: ${{ matrix.latest-python-version }} | |
| RELEASE_TAG: ${{ env.RELEASE_TAG }} | |
| IMAGE_NAME: apify/actor-${{ matrix.image-name }} | |
| # Force this to true, as these images have no browsers | |
| IS_LATEST_BROWSER_IMAGE: "true" | |
| with: | |
| script: | | |
| const generateTags = require("./.github/scripts/prepare-python-image-tags.js"); | |
| return generateTags() | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4 | |
| - name: Build and tag image for testing | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: ./${{ matrix.image-name }} | |
| file: ./${{ matrix.image-name }}/Dockerfile | |
| build-args: | | |
| PYTHON_VERSION=${{ matrix.python-version }} | |
| platforms: linux/amd64 | |
| provenance: false | |
| load: true | |
| tags: ${{ fromJson(steps.prepare-tags.outputs.result).allTags }} | |
| cache-from: type=gha,scope=${{ matrix.image-name }}-${{ matrix.python-version }} | |
| cache-to: type=gha,mode=max,scope=${{ matrix.image-name }}-${{ matrix.python-version }} | |
| - name: Test image | |
| run: docker run ${{ fromJson(steps.prepare-tags.outputs.result).firstImageName }} | |
| - name: Measure image size | |
| id: image-size | |
| if: github.event_name == 'pull_request' | |
| env: | |
| MATRIX_JSON: ${{ toJSON(matrix) }} | |
| NEW_IMAGE: ${{ fromJson(steps.prepare-tags.outputs.result).firstImageName }} | |
| BASE_IMAGE: apify/actor-${{ matrix.image-name }}:${{ matrix.python-version }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p size-report | |
| id="$(printf '%s' "$MATRIX_JSON" | sha256sum | cut -c1-16)" | |
| new_bytes="$(docker image inspect "$NEW_IMAGE" --format '{{.Size}}')" | |
| if docker pull --platform linux/amd64 "$BASE_IMAGE" >/dev/null 2>&1; then | |
| current_bytes="$(docker image inspect "$BASE_IMAGE" --format '{{.Size}}')" | |
| else | |
| current_bytes="" | |
| echo "No published baseline image found for ${BASE_IMAGE}" | |
| fi | |
| jq -n \ | |
| --argjson matrix "$MATRIX_JSON" \ | |
| --arg base "$BASE_IMAGE" \ | |
| --arg current "$current_bytes" \ | |
| --arg new "$new_bytes" \ | |
| '{matrix: $matrix, baseImage: $base, currentBytes: $current, newBytes: $new}' \ | |
| > "size-report/${id}.json" | |
| echo "id=${id}" >> "$GITHUB_OUTPUT" | |
| - name: Upload image size report | |
| if: github.event_name == 'pull_request' | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: image-size-${{ steps.image-size.outputs.id }} | |
| path: size-report/ | |
| retention-days: 1 | |
| - name: Login to DockerHub | |
| if: github.event_name != 'pull_request' | |
| uses: docker/login-action@v4 | |
| with: | |
| username: ${{ secrets.APIFY_SERVICE_ACCOUNT_DOCKERHUB_USERNAME }} | |
| password: ${{ secrets.APIFY_SERVICE_ACCOUNT_DOCKERHUB_TOKEN }} | |
| - name: Build and push OCI image | |
| if: github.event_name != 'pull_request' | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: ./${{ matrix.image-name }} | |
| file: ./${{ matrix.image-name }}/Dockerfile | |
| build-args: | | |
| PYTHON_VERSION=${{ matrix.python-version }} | |
| platforms: linux/amd64,linux/arm64 | |
| provenance: true | |
| push: true | |
| tags: ${{ fromJson(steps.prepare-tags.outputs.result).allTags }} | |
| outputs: type=image,oci-mediatypes=true | |
| cache-from: type=gha,scope=${{ matrix.image-name }}-${{ matrix.python-version }} | |
| # Aggregate the per-image size reports uploaded by the build matrix and post/update | |
| # a single sticky PR comment comparing current vs new image sizes. | |
| size-report: | |
| name: Report image size changes | |
| needs: [build-main] | |
| if: ${{ always() && github.event_name == 'pull_request' }} | |
| runs-on: ubuntu-latest | |
| permissions: | |
| pull-requests: write | |
| # All image workflows update sections of ONE shared PR comment; the repo-wide | |
| # concurrency group serializes their read-modify-write so no section is lost. | |
| concurrency: | |
| group: image-size-comment-${{ github.event.pull_request.number }} | |
| cancel-in-progress: false | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Download image size reports | |
| uses: actions/download-artifact@v8 | |
| continue-on-error: true | |
| with: | |
| pattern: image-size-* | |
| path: size-reports | |
| merge-multiple: true | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: 24 | |
| - name: Render comment section | |
| run: | | |
| mkdir -p size-reports | |
| node .github/scripts/format-image-size-report.ts size-reports "Python basic images" "${{ github.event.pull_request.head.sha }}" | tee image-size-comment.md | |
| - name: Post or update image size comment | |
| uses: actions/github-script@v8 | |
| env: | |
| SECTION_KEY: python | |
| with: | |
| script: | | |
| const { readFileSync } = require('node:fs'); | |
| const upsertSection = require('./.github/scripts/upsert-image-size-comment.js'); | |
| await upsertSection({ github, context }, process.env.SECTION_KEY, readFileSync('image-size-comment.md', 'utf8')); |