Repository navigation
perf(wsi): bound cold slide operations #39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and publish container | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| tags: ['*'] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| env: | |
| IMAGE_NAME: cbioportal/cbioportal-tile-server | |
| jobs: | |
| # Build once on amd64 and exercise health, readiness, auth, and CORS. This | |
| # gates publishing and runs on every pull request. | |
| container-smoke: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check out source | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| - name: Build image | |
| run: docker build --pull --tag tile-server:ci . | |
| - name: Exercise health, readiness, auth, and CORS | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| container_id="$(docker run --detach --rm \ | |
| --env WSI_AUTH_SECRET=0123456789abcdef0123456789abcdef \ | |
| --env REDIS_URL= \ | |
| --env N_WORKERS=1 \ | |
| --env CORS_ORIGINS=https://triage-beta.cbioportal.aws.mskcc.org \ | |
| --publish 18080:8080 tile-server:ci)" | |
| cleanup() { | |
| docker logs "$container_id" || true | |
| docker stop "$container_id" >/dev/null 2>&1 || true | |
| } | |
| trap cleanup EXIT | |
| for attempt in {1..30}; do | |
| if curl --fail --silent http://127.0.0.1:18080/health >/dev/null; then | |
| break | |
| fi | |
| sleep 1 | |
| done | |
| curl --fail --silent http://127.0.0.1:18080/health | |
| curl --fail --silent http://127.0.0.1:18080/ready | |
| test "$(curl --silent --output /dev/null --write-out '%{http_code}' \ | |
| http://127.0.0.1:18080/tiles/zxy/0/0/0?source=s3%3A%2F%2Fexample.invalid%2Fslide.svs)" = 401 | |
| cors_headers="$(curl --fail --silent --include --request OPTIONS \ | |
| --header 'Origin: https://triage-beta.cbioportal.aws.mskcc.org' \ | |
| --header 'Access-Control-Request-Method: GET' \ | |
| --header 'Access-Control-Request-Headers: authorization' \ | |
| --header 'Access-Control-Request-Private-Network: true' \ | |
| http://127.0.0.1:18080/tiles/zxy/0/0/0?source=s3%3A%2F%2Fexample.invalid%2Fslide.svs)" | |
| printf '%s\n' "$cors_headers" | grep -i '^access-control-allow-origin: https://triage-beta.cbioportal.aws.mskcc.org' | |
| printf '%s\n' "$cors_headers" | grep -i '^access-control-allow-private-network: true' | |
| ! docker logs "$container_id" 2>&1 | grep -q 'Control server error' | |
| # Build each architecture on its own native runner and push to the registry by | |
| # digest. The publish job below assembles the multi-arch manifest list. | |
| # See: https://docs.docker.com/build/ci/github-actions/multi-platform/ | |
| build: | |
| needs: container-smoke | |
| if: github.event_name == 'push' && github.repository == 'cBioPortal/cbioportal-tile-server' | |
| runs-on: ${{ matrix.runner }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - platform: linux/amd64 | |
| runner: ubuntu-24.04 | |
| - platform: linux/arm64 | |
| runner: ubuntu-24.04-arm | |
| steps: | |
| - name: Check out source | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| - name: Prepare platform pair | |
| env: | |
| platform: ${{ matrix.platform }} | |
| run: echo "PLATFORM_PAIR=${platform//\//-}" >> "$GITHUB_ENV" | |
| - name: Log in to Docker Hub | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: Build and push image by digest | |
| id: build | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| platforms: ${{ matrix.platform }} | |
| labels: org.opencontainers.image.revision=${{ github.sha }} | |
| # Per-arch cache scope so the two builds don't evict each other's | |
| # GitHub Actions cache. mode=max caches intermediate layers too. | |
| cache-from: type=gha,scope=tileserver-${{ env.PLATFORM_PAIR }} | |
| cache-to: type=gha,mode=max,scope=tileserver-${{ env.PLATFORM_PAIR }} | |
| outputs: type=image,name=${{ env.IMAGE_NAME }},push-by-digest=true,name-canonical=true,push=true | |
| - name: Export digest | |
| run: | | |
| mkdir -p "${{ runner.temp }}/digests" | |
| digest="${{ steps.build.outputs.digest }}" | |
| touch "${{ runner.temp }}/digests/${digest#sha256:}" | |
| - name: Upload digest | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: digests-${{ env.PLATFORM_PAIR }} | |
| path: ${{ runner.temp }}/digests/* | |
| if-no-files-found: error | |
| retention-days: 1 | |
| # Assemble the per-arch digests into a single multi-arch manifest list and tag | |
| # it. latest is generated automatically for a valid semver tag push. | |
| publish: | |
| needs: build | |
| if: github.event_name == 'push' && github.repository == 'cBioPortal/cbioportal-tile-server' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Download digests | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| path: ${{ runner.temp }}/digests | |
| pattern: digests-* | |
| merge-multiple: true | |
| - name: Extract metadata | |
| id: meta | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 | |
| with: | |
| images: ${{ env.IMAGE_NAME }} | |
| tags: | | |
| type=ref,event=branch | |
| type=ref,event=tag | |
| type=semver,pattern={{version}} | |
| - name: Log in to Docker Hub | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: Create manifest list and push | |
| working-directory: ${{ runner.temp }}/digests | |
| run: | | |
| # shellcheck disable=SC2046 # intentional: split tag flags and digests into separate args | |
| docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ | |
| $(printf '${{ env.IMAGE_NAME }}@sha256:%s ' *) | |
| - name: Inspect image | |
| run: docker buildx imagetools inspect ${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }} |