https://github.com/kameshsampath/apko-drone-plugin
Drone plugin to built tiny OCI container image using https://github.com/chainguard-dev/apko
https://github.com/kameshsampath/apko-drone-plugin
apko drone plugin
Last synced: about 1 month ago
JSON representation
Drone plugin to built tiny OCI container image using https://github.com/chainguard-dev/apko
- Host: GitHub
- URL: https://github.com/kameshsampath/apko-drone-plugin
- Owner: kameshsampath
- License: apache-2.0
- Created: 2023-02-06T14:00:51.000Z (over 3 years ago)
- Default Branch: main
- Last Pushed: 2023-02-09T06:33:35.000Z (over 3 years ago)
- Last Synced: 2025-10-20T12:38:09.298Z (9 months ago)
- Topics: apko, drone, plugin
- Language: Shell
- Homepage:
- Size: 22.5 KB
- Stars: 0
- Watchers: 1
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# Drone APKO Plugin
Drone plugin to built OCI container image using [apko](https://github.com/chainguard-dev/apko)
> **IMPORTANT:** This plugin is under development and the parameters are subject to change
## Usage
The following settings changes this plugin's behavior,
- `config_file`: The apko configuration YAML file, path relative to drone pipeline.
- `image_repo`: The fully qualified image repository where the built OCI image will be pushed.
- `publish`: Whether to publish the image to `image_repo`. Defaults to `false` which will just build the image tarball.
- `archs`: The `linux` architecture for which the images will be built. Defaults `$(uname -m)`. Valid values are: `amd64`, `arm64`.
- `build_output_dir`: The output directory relative to `config_file` where the build artifacts will be generated.
- `insecure`: Push to insecure registry.
### Container Registry Credentials
- `image_registry_username`: The user name that will be used to push the image to `image_repo`. Applicable when the `image_repo` is not GAR, ECR.
- `image_registry_password`: The user password that will be used to push the image to `image_repo`. Applicable when the `image_repo` is not GAR, ECR.
### Google Artifact Registry Credentials
- `google_application_credentials`: The base64 encoded Google application credentials i.e. SA key.json. This parameter is useful only when your `image_repo` is [Google Artifact registry](https://cloud.google.com/artifact-registry/docs)
### Elastic Container Registry Credentials
- `aws_access_key_id`: The AWS `AWS_ACCESS_KEY_ID`
- `aws_secret_access_key`: The AWS `AWS_SECRET_ACCESS_KEY`
```yaml
kind: pipeline
type: docker
name: default
steps:
- name: build image
image: kameshsampath/apko-drone-plugin
settings:
config_file: image.yaml
image_repo: example/hello-world:0.0.1
publish: false
archs:
- amd64
- arm64
```
Now load the image using the command,
```shell
docker load < ./dist/hello-world-0.0.1_$(uname -m).tar
```
## Examples
Checkout examples in folder [examples](./examples/). You need to have [drone](https://docs.drone.io/cli/install/) CLI to execute the examples locally.
| Example | Description |
| :--------------------------------------------------------------------------------- | :------------------------------------------------------------------------- |
| [Any OCI Registry](./examples/any-registry/README.md) | Build and deploy to any OCI compliant registry |
| [Any OCI Registry Multi Architecture](./examples/any-registry-multiarch/README.md) | Build and deploy multi architecture images to any OCI compliant registry |
| [Elastic Container Registry](./examples/ecr/README.md) | Build and deploy to Elastic Container Registry(ECR) |
| [Google Artifact Registry](./examples/gar/README.md) | Build and deploy to Google Artifact registry(GAR) |
| [No Push](./examples/tarball/README.md) | Build OCI tarball without pushing to remote repository. |
| [Multi Architecture](./examples/tarball-multiarch/README.md) | Build multi architecture OCI tarball without pushing to remote repository. |
## Building Plugin
The plugin relies on [apko](https://github.com/chainguard-dev/apko) and [melange](https://github.com/chainguard-dev/melange) for build.
The plugin build relies on:
- [crane](https://github.com/google/go-containerregistry)
- [limactl](https://github.com/lima-vm/lima)
- [taskfile](https://taskfile.dev)
Start `lima-vm` environment,
```shell
task build_env
```
Build plugin packages,
```shell
task build_plugin_packages
```
Build plugin container image,
```shell
task build_plugin
```
To publish the plugin to remote repository use,
```shell
task publish_plugin
```
## Testing
Build plugin packages,
```shell
task build_plugin load
```
Build plugin container image,
```shell
task build_plugin
```
Create `.env`
```shell
cat< **NOTE**: the command generates the OCI image tarball in director dist
```shell
docker load < "$PWD/dist/example/my-image_$(uname -m).tar
```
Now run the image to see the text **Hello, welcome to apko world**,
```shell
docker run -it --rm example/my-image
```