Template repo for clbsoldev Docker images: build → content digest comparison
→ publish to GHCR (optionally Docker Hub), multi-arch (linux/amd64,linux/arm64).
- "Use this template" → create a new repo. Repo name = resulting image name
(e.g. repo
syslog-logdy-server→ghcr.io/clbsoldev/syslog-logdy-server). The workflow derives the image name from the repo name automatically —.github/workflows/build.ymldoes not need to be changed for this. - Replace the entire
image/directory with your actual image. - Pin the base image by digest:
Enter the top-level digest (manifest list, not
docker buildx imagetools inspect <image>:<tag>
docker inspect— that one only reflects the local host's architecture and would break arm64 builds) into the Dockerfile. - Replace
Readme.mdandChangelog.mdwith project-specific content. - If Docker Hub should be used: set the repo variable
ENABLE_DOCKERHUB=true, addDOCKERHUB_USERNAME/DOCKERHUB_TOKENas secrets, and add ashort-descriptionto thedockerhub-descriptionstep inbuild.yml(that's project-specific text and can't be derived generically).
- Image name: derived automatically from the repo name, with a leading
docker-prefix stripped if present (matches thedocker-<name>repo naming convention, e.g. repodocker-syslog-logdy-server→ imageghcr.io/clbsoldev/syslog-logdy-server). No workflow edit needed per repo. - Publish gate: the
checkjob hashes the built OCI tarball and compares it againstdigest.txtfrom the last run. Only if the content actually changed doespublishrun — so a weekly cron rebuild with no real change (e.g. base image unchanged) doesn't spam a new:latestpush. - Docker Hub is off by default. To enable it on a given repo: set the
repo variable
ENABLE_DOCKERHUB=true(Settings → Secrets and variables → Actions → Variables), and addDOCKERHUB_USERNAME/DOCKERHUB_TOKENas secrets. Without the variable, both Docker Hub steps are skipped entirely — GHCR publishing always happens regardless of this toggle.
.github/labels.yml is automatically synced to the repo on every push that
changes this file (label-sync.yml, via micnncim/action-label-syncer). Just
add/change labels there and push.
GitHub does not copy repository labels when using "Use this template" —
only files. That's what the separate label-sync.yml workflow is for: it
runs automatically on the first push to main in the new repo and creates
the labels from labels.yml, with no manual step required.