diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index ab69575..0dde694 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -280,8 +280,26 @@ jobs: cat publish-record.json exit 0 fi - docker image inspect omarchy-pkg-builder:latest-x86_64-edge >/dev/null 2>&1 \ - || docker buildx build --load -t omarchy-pkg-builder:latest-x86_64-edge --build-arg MIRROR=edge build + # A builder droplet starts with no images, so building this one here + # cost every publish about 100 s (and 20 s more to start a container + # from it) for the 14 s of signing and upload it is needed for. + # builder-images.yml already publishes the tested image for exactly + # these build inputs under their key; pull that. Build only when no + # image carries the key: a merge that changed build/ publishes + # before the refresh it triggered has finished. + builder=omarchy-pkg-builder:latest-x86_64-edge + if ! docker image inspect "$builder" >/dev/null 2>&1; then + key=$(bin/builder-image key --arch x86_64 --mirror edge) + published="ghcr.io/omacom/omarchy-pkg-builder:$key" + if docker pull --quiet "$published" && + [[ $(docker image inspect "$published" --format '{{index .Config.Labels "org.omarchy.builder.key"}}') == "$key" ]]; then + docker tag "$published" "$builder" + echo "==> Builder image: pulled $published" + else + echo "==> Builder image: none published for $key, building it" + docker buildx build --load -t "$builder" --build-arg MIRROR=edge build + fi + fi # Group the merge's files by the (channel, architecture) slot each # belongs to. A package's files live under build-output/edge/