diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..799e7f2 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,15 @@ +--- +version: 2 +updates: + - package-ecosystem: docker + directory: / + schedule: + interval: weekly + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + - package-ecosystem: docker + directory: /tests + schedule: + interval: weekly \ No newline at end of file diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml new file mode 100644 index 0000000..51b5a03 --- /dev/null +++ b/.github/workflows/docker-publish.yml @@ -0,0 +1,86 @@ +name: Docker apple idendity provider keycloak +'on': + push: + tags: + - '*' +jobs: + docker: + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - name: Checkout + uses: actions/checkout@v3 + - name: Repo metadata + id: repo + uses: actions/github-script@v4 + with: + script: | + const repo = await github.repos.get(context.repo) + return repo.data + - name: Prepare + id: prep + run: | + REG=ghcr.io + IMAGE=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]') + DOCKER_IMAGE=${REG}/${IMAGE} + VERSION=nool + if [ "${{ github.event_name }}" = "schedule" ]; then + VERSION=nightly + elif [[ $GITHUB_REF == refs/tags/* ]]; then + VERSION=${GITHUB_REF#refs/tags/} + elif [[ $GITHUB_REF == refs/heads/* ]]; then + VERSION=$(echo ${GITHUB_REF#refs/heads/} | sed -r 's#/+#-#g') + if [ "${{ github.event.repository.default_branch }}" = "$VERSION" ]; then + VERSION=latest + fi + elif [[ $GITHUB_REF == refs/pull/* ]]; then + VERSION=pr-${{ github.event.number }} + fi + TAGS="${DOCKER_IMAGE}:${VERSION}" + if [[ $VERSION =~ ^v[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$ ]]; then + MINOR=${VERSION%.*} + MAJOR=${MINOR%.*} + TAGS="$TAGS,${DOCKER_IMAGE}:${MINOR},${DOCKER_IMAGE}:${MAJOR},${DOCKER_IMAGE}:latest" + fi + echo ::set-output name=version::${VERSION} + echo ::set-output name=tags::${TAGS} + echo ::set-output name=created::$(date -u +'%Y-%m-%dT%H:%M:%SZ') + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v2 + - name: Login to GitHub Container Registry + uses: docker/login-action@v2 + with: + registry: ghcr.io + username: '${{ github.actor }}' + password: '${{ secrets.GITHUB_TOKEN }}' + - name: Build and push + uses: docker/build-push-action@v4 + with: + context: . + file: ./Dockerfile + platforms: linux/amd64 + push: true + tags: '${{ steps.prep.outputs.tags }}' + labels: > + org.opencontainers.image.title=${{ + fromJson(steps.repo.outputs.result).name }} + + org.opencontainers.image.description=${{ + fromJson(steps.repo.outputs.result).description }} + + org.opencontainers.image.url=${{ + fromJson(steps.repo.outputs.result).html_url }} + + org.opencontainers.image.source=${{ + fromJson(steps.repo.outputs.result).html_url }} + + org.opencontainers.image.version=${{ steps.prep.outputs.version }} + + org.opencontainers.image.created=${{ steps.prep.outputs.created }} + + org.opencontainers.image.revision=${{ github.sha }} + + org.opencontainers.image.licenses=${{ + fromJson(steps.repo.outputs.result).license.spdx_id }} \ No newline at end of file diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..14af555 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,21 @@ +FROM quay.io/keycloak/keycloak:22.0.1 as builder + +ENV KC_HEALTH_ENABLED=true +ENV KC_FEATURES=token-exchange +ENV KC_DB=postgres +ENV KC_HTTP_RELATIVE_PATH="/auth" + +# Install custom providers + +# Apple Social Identity Provider - https://github.com/klausbetz/apple-identity-provider-keycloak +ADD --chown=keycloak:keycloak https://github.com/klausbetz/apple-identity-provider-keycloak/releases/download/1.7.0/apple-identity-provider-1.7.0.jar /opt/keycloak/providers/apple-identity-provider-1.7.0.jar + +# build optimized image +RUN /opt/keycloak/bin/kc.sh build + +FROM quay.io/keycloak/keycloak:22.0.1 + +COPY --from=builder /opt/keycloak/ /opt/keycloak/ +WORKDIR /opt/keycloak + +ENTRYPOINT ["/opt/keycloak/bin/kc.sh"] \ No newline at end of file