name: 'Setup BuildKit (with labels)' description: 'Idempotently start a labeled buildkitd container and point buildx at it via the remote driver. The default docker-container driver cannot set container labels, and the Docker API has no PATCH-labels for existing containers — so we manage the container ourselves and Watchtower/Dockhand see the labels.' inputs: container_name: description: 'Name of the buildkitd container' required: false default: 'buildkitd' image: description: 'BuildKit image' required: false default: 'moby/buildkit:buildx-stable-1' monitor_only: description: 'Value for com.centurylinklabs.watchtower.monitor-only' required: false default: 'false' dockhand_notify: description: 'Value for dockhand.notify' required: false default: 'false' cleanup: description: 'Stop the buildkitd container after the job (idle cleanup; container restarts on demand on the next run)' required: false default: 'true' network: description: 'Docker network for the buildkitd container — MUST match the network the job containers run on, otherwise the name is unresolvable' required: false default: 'git_default' port: description: 'TCP port buildkitd listens on' required: false default: '8375' runs: using: 'composite' steps: - name: Start BuildKit container (with labels) shell: bash run: | docker ps -a --format '{{.Names}}' | grep -qx '${{ inputs.container_name }}' || \ docker run -d --name ${{ inputs.container_name }} --privileged \ --network ${{ inputs.network }} \ --restart unless-stopped \ --label com.centurylinklabs.watchtower.monitor-only=${{ inputs.monitor_only }} \ --label dockhand.notify=${{ inputs.dockhand_notify }} \ ${{ inputs.image }} --addr tcp://0.0.0.0:${{ inputs.port }} - name: Set up Docker Buildx uses: docker/setup-buildx-action@v4 with: driver: remote endpoint: tcp://${{ inputs.container_name }}:${{ inputs.port }} - name: Stop BuildKit (idle cleanup) if: ${{ inputs.cleanup == 'true' && always() }} shell: bash run: docker stop ${{ inputs.container_name }} || true