Skip to content

Python basic images #6573

Python basic images

Python basic images #6573

name: Python basic images
on:
workflow_dispatch:
inputs:
release_tag:
description: 'Tag for the images (e.g.: "latest" or "beta")'
required: true
rebuild_images:
description: "Rebuilds images even if the cache state matches the current state."
required: false
type: boolean
trigger_templates_pr:
description: "When set to true, always triggers the workflow on actor-templates."
required: false
type: boolean
repository_dispatch:
types: [build-python-images]
pull_request:
paths:
- "python/**"
- ".github/workflows/release-python.yaml"
- ".github/actions/version-matrix/**"
- ".github/scripts/prepare-python-image-tags.js"
- "Makefile"
schedule:
- cron: 0 */2 * * *
env:
RELEASE_TAG: ${{ github.event.inputs.release_tag || github.event.client_payload.release_tag }}
SKIP_CACHE_CHECK: ${{ github.event_name == 'pull_request' || github.event.inputs.rebuild_images == 'true' }}
jobs:
matrix:
runs-on: ubuntu-latest
outputs:
matrix: ${{ steps.set-matrix.outputs.matrix }}
steps:
- uses: actions/checkout@v6
with:
token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }}
fetch-depth: 0
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version-file: .github/actions/version-matrix/package.json
cache: yarn
cache-dependency-path: .github/actions/version-matrix/yarn.lock
- run: yarn
working-directory: ./.github/actions/version-matrix
- name: Generate matrix
id: set-matrix
run: echo "matrix=$(yarn python:normal)" >> $GITHUB_OUTPUT
working-directory: ./.github/actions/version-matrix
- name: Print matrix
run: |
echo '${{ steps.set-matrix.outputs.matrix }}' | jq -r '.include[] | "python-version=\(.["python-version"])"'
echo ""
echo "Raw matrix:"
echo ""
echo '${{ steps.set-matrix.outputs.matrix }}' | jq -e
- name: Commit updated matrix
id: commit
if: github.event_name != 'pull_request'
uses: apify/actions/signed-commit@v1.2.0
with:
message: "chore(docker): update ${{ env.RELEASE_TAG || 'latest' }} python:normal cache"
add: ./.github/actions/version-matrix/data/*.json
retries: 5
pull: '--rebase --autostash'
github-token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }}
- name: Trigger workflow on actor-templates
if: (steps.commit.outputs.committed == 'true' || github.event.inputs.trigger_templates_pr == 'true') && steps.set-matrix.outputs.latest-runtime-version != ''
uses: peter-evans/repository-dispatch@v4
with:
token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }}
repository: apify/actor-templates
event-type: update-templates
client-payload: |-
{
"base_image": "apify/actor-python",
"default_runtime_version": "${{ steps.set-matrix.outputs.latest-runtime-version }}"
}
# Build master images that are not dependent on existing builds.
build-main:
needs: [matrix]
runs-on: ubuntu-latest
if: ${{ toJson(fromJson(needs.matrix.outputs.matrix).include) != '[]' }}
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.matrix.outputs.matrix) }}
name: "py: ${{ matrix.python-version }}"
steps:
- name: Set default inputs if event is pull request
if: github.event_name == 'pull_request'
run: |
if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG=CI_TEST" >> $GITHUB_ENV; fi
- name: Set default inputs if event is schedule
if: github.event_name == 'schedule'
run: |
if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG=latest" >> $GITHUB_ENV; fi
- name: Check if inputs are set correctly
run: |
if [[ -z "$RELEASE_TAG" ]]; then echo "RELEASE_TAG input is empty!" >&2; exit 1; fi
- name: Checkout
uses: actions/checkout@v6
- name: Prepare image tags
id: prepare-tags
uses: actions/github-script@v8
env:
CURRENT_PYTHON: ${{ matrix.python-version }}
LATEST_PYTHON: ${{ matrix.latest-python-version }}
RELEASE_TAG: ${{ env.RELEASE_TAG }}
IMAGE_NAME: apify/actor-${{ matrix.image-name }}
# Force this to true, as these images have no browsers
IS_LATEST_BROWSER_IMAGE: "true"
with:
script: |
const generateTags = require("./.github/scripts/prepare-python-image-tags.js");
return generateTags()
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Build and tag image for testing
uses: docker/build-push-action@v6
with:
context: ./${{ matrix.image-name }}
file: ./${{ matrix.image-name }}/Dockerfile
build-args: |
PYTHON_VERSION=${{ matrix.python-version }}
platforms: linux/amd64
provenance: false
load: true
tags: ${{ fromJson(steps.prepare-tags.outputs.result).allTags }}
cache-from: type=gha,scope=${{ matrix.image-name }}-${{ matrix.python-version }}
cache-to: type=gha,mode=max,scope=${{ matrix.image-name }}-${{ matrix.python-version }}
- name: Test image
run: docker run ${{ fromJson(steps.prepare-tags.outputs.result).firstImageName }}
- name: Measure image size
id: image-size
if: github.event_name == 'pull_request'
env:
MATRIX_JSON: ${{ toJSON(matrix) }}
NEW_IMAGE: ${{ fromJson(steps.prepare-tags.outputs.result).firstImageName }}
BASE_IMAGE: apify/actor-${{ matrix.image-name }}:${{ matrix.python-version }}
run: |
set -euo pipefail
mkdir -p size-report
id="$(printf '%s' "$MATRIX_JSON" | sha256sum | cut -c1-16)"
new_bytes="$(docker image inspect "$NEW_IMAGE" --format '{{.Size}}')"
if docker pull --platform linux/amd64 "$BASE_IMAGE" >/dev/null 2>&1; then
current_bytes="$(docker image inspect "$BASE_IMAGE" --format '{{.Size}}')"
else
current_bytes=""
echo "No published baseline image found for ${BASE_IMAGE}"
fi
jq -n \
--argjson matrix "$MATRIX_JSON" \
--arg base "$BASE_IMAGE" \
--arg current "$current_bytes" \
--arg new "$new_bytes" \
'{matrix: $matrix, baseImage: $base, currentBytes: $current, newBytes: $new}' \
> "size-report/${id}.json"
echo "id=${id}" >> "$GITHUB_OUTPUT"
- name: Upload image size report
if: github.event_name == 'pull_request'
uses: actions/upload-artifact@v7
with:
name: image-size-${{ steps.image-size.outputs.id }}
path: size-report/
retention-days: 1
- name: Login to DockerHub
if: github.event_name != 'pull_request'
uses: docker/login-action@v4
with:
username: ${{ secrets.APIFY_SERVICE_ACCOUNT_DOCKERHUB_USERNAME }}
password: ${{ secrets.APIFY_SERVICE_ACCOUNT_DOCKERHUB_TOKEN }}
- name: Build and push OCI image
if: github.event_name != 'pull_request'
uses: docker/build-push-action@v6
with:
context: ./${{ matrix.image-name }}
file: ./${{ matrix.image-name }}/Dockerfile
build-args: |
PYTHON_VERSION=${{ matrix.python-version }}
platforms: linux/amd64,linux/arm64
provenance: true
push: true
tags: ${{ fromJson(steps.prepare-tags.outputs.result).allTags }}
outputs: type=image,oci-mediatypes=true
cache-from: type=gha,scope=${{ matrix.image-name }}-${{ matrix.python-version }}
# Aggregate the per-image size reports uploaded by the build matrix and post/update
# a single sticky PR comment comparing current vs new image sizes.
size-report:
name: Report image size changes
needs: [build-main]
if: ${{ always() && github.event_name == 'pull_request' }}
runs-on: ubuntu-latest
permissions:
pull-requests: write
# All image workflows update sections of ONE shared PR comment; the repo-wide
# concurrency group serializes their read-modify-write so no section is lost.
concurrency:
group: image-size-comment-${{ github.event.pull_request.number }}
cancel-in-progress: false
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Download image size reports
uses: actions/download-artifact@v8
continue-on-error: true
with:
pattern: image-size-*
path: size-reports
merge-multiple: true
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version: 24
- name: Render comment section
run: |
mkdir -p size-reports
node .github/scripts/format-image-size-report.ts size-reports "Python basic images" "${{ github.event.pull_request.head.sha }}" | tee image-size-comment.md
- name: Post or update image size comment
uses: actions/github-script@v8
env:
SECTION_KEY: python
with:
script: |
const { readFileSync } = require('node:fs');
const upsertSection = require('./.github/scripts/upsert-image-size-comment.js');
await upsertSection({ github, context }, process.env.SECTION_KEY, readFileSync('image-size-comment.md', 'utf8'));