2026-09-01 11:52:19 +02:00
name : 'Setup BuildKit (with labels)'
description : 'Idempotently start a labeled buildkitd container and point buildx at it via the remote driver. The default docker-container driver cannot set container labels, and the Docker API has no PATCH-labels for existing containers — so we manage the container ourselves and Watchtower/Dockhand see the labels.'
inputs :
container_name :
description : 'Name of the buildkitd container'
required : false
default : 'buildkitd'
image :
description : 'BuildKit image'
required : false
default : 'moby/buildkit:buildx-stable-1'
monitor_only :
description : 'Value for com.centurylinklabs.watchtower.monitor-only'
required : false
default : 'false'
dockhand_notify :
description : 'Value for dockhand.notify'
required : false
default : 'false'
cleanup :
2026-09-01 11:54:03 +02:00
description : 'Stop the buildkitd container after the job (idle cleanup; container restarts on demand on the next run)'
2026-09-01 11:52:19 +02:00
required : false
2026-09-01 11:54:03 +02:00
default : 'true'
2026-09-01 13:12:43 +02:00
network :
description : 'Docker network for the buildkitd container — MUST match the network the job containers run on, otherwise the name is unresolvable'
required : false
default : 'git_default'
port :
description : 'TCP port buildkitd listens on'
required : false
default : '8375'
2026-09-01 11:52:19 +02:00
runs :
using : 'composite'
steps :
- name : Start BuildKit container (with labels)
shell : bash
run : |
2026-09-01 13:29:26 +02:00
# Recreate if a stopped/old container exists (config drift, e.g. port
# mapping changes, would otherwise be skipped by the name guard).
# If it is already running with the right config, keep it (warm cache).
if [ "$(docker inspect -f '{{.State.Running}}' ${{ inputs.container_name }} 2>/dev/null)" != "true" ]; then
docker rm -f ${{ inputs.container_name }} >/dev/null 2>&1 || true
2026-09-01 13:40:02 +02:00
# NOTE: no -p publish needed — the job executor itself runs on the
# same docker network, so it reaches buildkitd by container DNS name.
# (127.0.0.1 inside the executor is its own loopback, NOT the host's.)
2026-09-01 13:29:26 +02:00
docker run -d --name ${{ inputs.container_name }} --privileged \
--network ${{ inputs.network }} \
--restart unless-stopped \
--label com.centurylinklabs.watchtower.monitor-only=${{ inputs.monitor_only }} \
--label dockhand.notify=${{ inputs.dockhand_notify }} \
${{ inputs.image }} --addr tcp://0.0.0.0:${{ inputs.port }}
fi
2026-09-01 11:52:19 +02:00
- name : Set up Docker Buildx
uses : docker/setup-buildx-action@v4
with :
driver : remote
2026-09-01 13:40:02 +02:00
endpoint : tcp://${{ inputs.container_name }}:${{ inputs.port }}
2026-09-01 11:52:19 +02:00
- name : Stop BuildKit (idle cleanup)
if : ${{ inputs.cleanup == 'true' && always() }}
shell : bash
run : docker stop ${{ inputs.container_name }} || true