如何通过GitHub Actions实现多仓库整合的Nginx镜像自动构建并推送至ECR(用于ECS多站点部署)
Great question—this is a common scenario when managing multiple related sites across separate repos. Let’s walk through two solid approaches to automate building a single Nginx image with all your simulator sites and pushing it to ECR, using GitHub Actions.
Approach 1: Use a Central "Build Hub" Repository
This is the most straightforward method: create a dedicated repo to orchestrate pulling all your simulator code, building the Nginx image, and pushing it to ECR.
Step 1: Set Up the Central Repository
Create a repo (e.g., nginx-multi-site-build) to act as your build hub. Inside it, you’ll need:
- A
Dockerfileto package all sites into Nginx - A custom Nginx config file to route traffic to each site
- A GitHub Actions workflow to handle automation
Example Dockerfile
# Use official Nginx Alpine image for smaller size FROM nginx:alpine # Copy each simulator's site content to distinct Nginx directories COPY simulator_1 /usr/share/nginx/html/simulator1 COPY simulator_2 /usr/share/nginx/html/simulator2 COPY simulator_3 /usr/share/nginx/html/simulator3 # Override default Nginx config with your multi-site setup COPY nginx.conf /etc/nginx/nginx.conf
Example Nginx Config (nginx.conf snippet)
http { include /etc/nginx/mime.types; default_type application/octet-stream; server { listen 80; server_name simulator1.yourcompany.com; root /usr/share/nginx/html/simulator1; index index.html index.htm; } server { listen 80; server_name simulator2.yourcompany.com; root /usr/share/nginx/html/simulator2; index index.html index.htm; } server { listen 80; server_name simulator3.yourcompany.com; root /usr/share/nginx/html/simulator3; index index.html index.htm; } }
Step 2: Pull Simulator Code into the Hub
You have two options to fetch code from your simulator_* repos:
Option A: Git Submodules
Link each simulator repo as a submodule in your build hub:
# Run these in your build hub repo git submodule add https://github.com/yourcompany/simulator_1.git git submodule add https://github.com/yourcompany/simulator_2.git git submodule add https://github.com/yourcompany/simulator_3.git git commit -m "Add simulator submodules" git push
Option B: Scripted Git Clone
If submodules feel too rigid, use a bash script to pull the latest code during the Actions workflow. Create a pull-simulators.sh file:
#!/bin/bash git clone https://${GH_PAT}@github.com/yourcompany/simulator_1.git git clone https://${GH_PAT}@github.com/yourcompany/simulator_2.git git clone https://${GH_PAT}@github.com/yourcompany/simulator_3.git
Make sure to mark it executable: chmod +x pull-simulators.sh
Step 3: Configure GitHub Actions Workflow
Create .github/workflows/build-push-ecr.yml to automate builds and pushes:
name: Build Multi-Site Nginx Image & Push to ECR on: push: branches: [ main ] # Trigger builds when any simulator repo updates (see Step 4) repository_dispatch: types: [ simulator-updated ] jobs: build-and-push: runs-on: ubuntu-latest steps: - name: Checkout Build Hub Repo uses: actions/checkout@v4 # Uncomment if using submodules # with: # submodules: recursive # Uncomment if using scripted clone instead of submodules # - name: Pull Latest Simulator Code # env: # GH_PAT: ${{ secrets.GH_PAT }} # run: ./pull-simulators.sh - name: Configure AWS Credentials uses: aws-actions/configure-aws-credentials@v4 with: aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-region: us-east-1 # Replace with your ECR region - name: Login to Amazon ECR id: login-ecr uses: aws-actions/amazon-ecr-login@v2 - name: Build, Tag, & Push Image env: ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }} ECR_REPOSITORY: your-multi-site-nginx # Replace with your ECR repo name IMAGE_TAG: ${{ github.sha }} # Use commit hash for traceability run: | docker build -t $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG . docker push $ECR_REGISTRY/$ECR_REPOSITORY:$IMAGE_TAG
Step 4: Trigger Builds When Simulators Update
To ensure your image stays up-to-date when any simulator repo changes, add a workflow to each simulator_* repo (e.g., .github/workflows/trigger-hub-build.yml):
name: Trigger Multi-Site Build on: push: branches: [ main ] jobs: trigger-hub: runs-on: ubuntu-latest steps: - name: Dispatch Event to Build Hub uses: peter-evans/repository-dispatch@v3 with: token: ${{ secrets.GH_PAT }} repository: yourcompany/nginx-multi-site-build event-type: simulator-updated
Approach 2: Cross-Repo Artifact Sharing
If you want each simulator repo to handle its own static build (e.g., React/Vue sites), you can:
- Each simulator repo builds its static assets and uploads them as a GitHub Artifact.
- The build hub repo listens for updates, downloads all artifacts, and packages them into the Nginx image.
This is useful if your simulators require build steps (like npm install/build) before producing static files. The core workflow would be similar to Approach 1, but instead of pulling raw code, you’d use the actions/download-artifact action to fetch pre-built assets from each simulator’s latest workflow run.
Key Notes
- Permissions: Create a GitHub PAT with
reposcope to access private simulator repos, and AWS IAM credentials withecr:GetAuthorizationToken,ecr:BatchCheckLayerAvailability,ecr:BatchGetImage,ecr:InitiateLayerUpload,ecr:UploadLayerPart,ecr:CompleteLayerUpload, andecr:PutImagepermissions. - Caching: Add Docker layer caching to your workflow with
actions/cacheto speed up repeated builds. - Testing: Add a step to run the built image and validate Nginx config (e.g.,
docker run -d -p 8080:80 $IMAGE_TAG && curl http://localhost:8080/simulator1).
内容的提问来源于stack exchange,提问作者Baptiste Audugé

