GitHub Action to build and push Docker images with Buildx
GitHub Action to build and push Docker images with Buildx
GitHub Action to build and push Docker images with Buildx with full support of the features provided by Moby BuildKit builder toolkit. This includes multi-platform build, secrets, remote cache, etc. and different builder deployment/namespacing options.
In the examples below we are also using 3 other actions:
setup-buildx action will
create and boot a builder using by default the docker-container driver.
This is not required but recommended using it to be able to build
multi-platform images, export cache, etc.setup-qemu action can be
useful if you want to add emulation support with QEMU to be able to build
against more platforms. login action will take care to
log in against a Docker registry.By default, this action uses the Git context,
so you don't need to use the actions/checkout
action to check out the repository as this will be done directly by BuildKit.
The git reference will be based on the event that triggered your workflow
and will result in the following context: https://github.com/<owner>/<repo>.git#<ref>.
name: ci
on:
push:
jobs:
docker:
runs-on: ubuntu-latest
steps:
-
name: Login to Docker Hub
uses: docker/login-action@v4
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
-
name: Set up QEMU
uses: docker/setup-qemu-action@v4
-
name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
-
name: Build and push
uses: docker/build-push-action@v7
with:
push: true
tags: user/app:latest
Be careful because any file mutation in the steps that precede the build step
will be ignored, including processing of the .dockerignore file since
the context is based on the Git reference. However, you can use the
Path context using the context input alongside
the actions/checkout action to remove
this restriction.
Default Git context can also be provided using the Handlebars template
expression {{defaultContext}}. Here we can use it to provide a subdirectory
to the default Git context:
-
name: Build and push
uses: docker/build-push-action@v7
with:
context: "{{defaultContext}}:mysubdir"
push: true
tags: user/app:latest
Building from the current repository automatically uses the GitHub Token,
so it does not need to be passed. If you want to authenticate against another
private repository, you have to use a secret
named GIT_AUTH_TOKEN to be able to authenticate against it with Buildx:
-
name: Build and push
uses: docker/build-push-action@v7
with:
push: true
tags: user/app:latest
secrets: |
GIT_AUTH_TOKEN=${{ secrets.MYTOKEN }}
…
This action generates a job summary that provides a detailed overview of the build execution. The summary shows an overview of all the steps executed during the build, including the build inputs and eventual errors.
The summary also includes a link for downloading the build record with additional details about the build, including build stats, logs, outputs, and more. The build record can be imported to Docker Desktop for inspecting the build in greater detail.
[!WARNING]
If you're using the
actions/download-artifactaction in your workflow, you need to ignore the build record artifacts ifnameandpatterninputs are not specified (defaults to download all artifacts of the workflow), otherwise the action will fail:- uses: actions/download-artifact@v4 with: pattern: "!*.dockerbuild"More info: https://github.com/actions/toolkit/pull/1874
Summaries are enabled by default, but can be disabled with the
DOCKER_BUILD_SUMMARY environment variable.
For more information about summaries, refer to the documentation.
The following inputs can be used as step.with keys:
Listtype is a newline-delimited stringcache-from: | user/app:cache type=local,src=path/to/dir
Name Type Description
CSVtype is a comma-delimited stringtags: name/app:latest,name/app:1.0.0
add-hosts
List/CSV
List of customs host-to-IP mapping (e.g., docker:10.180.0.1)
allow
List/CSV
List of extra privileged entitlement (e.g., network.host,security.insecure)
annotations
List
List of annotation to set to the image
attests
List
List of attestation parameters (e.g., type=sbom,generator=image)
builder
String
Builder instance (see setup-buildx action)
build-args
List
List of build-time variables
build-contexts
List
List of additional build contexts (e.g., name=path)
cache-from
List
List of external cache sources (e.g., type=local,src=path/to/dir)
cache-to
List
List of cache export destinations (e.g., type=local,dest=path/to/dir)
call
String
Set method for evaluating build (e.g., check)
cgroup-parent
String
Optional parent cgroup for the container used in the build
context
String
Build's context is the set of files located in the specified PATH or URL (default Git context)
file
String
Path to the Dockerfile. (default {context}/Dockerfile)
labels
List
List of metadata for an image
load
Bool
Load is a shorthand for --output=type=docker (default false)
network
String
Set the networking mode for the RUN instructions during build
no-cache
Bool
Do not use cache when building the image (default false)
no-cache-filters
List/CSV
Do not cache specified stages
outputs
List
List of output destinations (format: type=local,dest=path)
platforms
List/CSV
List of target platforms for build
`prove
No open issues yet, or sync has not completed.