This directory contains automated workflows for the Flashpoint Web project.
Builds and pushes the single Docker image to the container registry.
- Version tags (
v*.*.*): Builds and pushes the image with version tags andlatesttag - Manual dispatch: Can be triggered manually from GitHub Actions tab
flashpoint-web- Single image serving both the REST API (including game content) and the React web UI
The workflow pushes images to Docker Hub.
-
Create Docker Hub account at https://hub.docker.com
-
Create access token:
- Go to Account Settings → Security → Access Tokens
- Click "New Access Token"
- Name: "GitHub Actions"
- Permissions: Read & Write
- Copy the token (you won't see it again!)
-
Add GitHub Secrets:
- Go to your repository → Settings → Secrets and variables → Actions
- Click "New repository secret"
- Add two secrets:
DOCKERHUB_USERNAME: Your Docker Hub usernameDOCKERHUB_TOKEN: The access token from step 2
-
Image will be pushed to:
docker.io/darkraise/flashpoint-web:latest
The workflow automatically creates multiple tags when you push a version tag:
| Tag Type | Example | Description |
|---|---|---|
latest |
latest |
Always created for every version tag |
| Full version | 1.2.3 |
Git tag v1.2.3 → 1.2.3 |
| Major.Minor | 1.2 |
Git tag v1.2.3 → 1.2 |
| Major | 1 |
Git tag v1.2.3 → 1 |
To create a versioned release:
# Ensure you're on master branch
git checkout master
# Tag the commit
git tag v1.0.0
# Push the tag (this triggers the workflow)
git push origin v1.0.0This will create images tagged as:
1.0.01.01latest
Images are built for:
linux/amd64(x86_64) - Standard servers and desktops
Note: ARM64 support has been disabled to significantly reduce build times. If you need ARM64 images, you can build them locally or enable multi-platform builds by adding linux/arm64 to the platforms in the workflow file.
The workflow uses GitHub Actions cache to speed up builds:
- Layer cache stored between runs
- Significantly faster builds after the first run
- Cache automatically invalidated when dependencies change
# Pull the latest image
docker pull darkraise/flashpoint-web:latest
# Or use a specific version
docker pull darkraise/flashpoint-web:1.0.0Update your docker-compose.yml to use the pre-built image:
services:
flashpoint-web:
image: darkraise/flashpoint-web:latest
# Remove build section
ports:
- "80:3100"
# ... rest of configThen simply run:
docker compose pull # Pull the latest image
docker compose up -d # Start the serviceBy default, Docker Hub images are private. To make them public:
- Go to https://hub.docker.com/repositories
- Click on the repository (e.g.,
flashpoint-web) - Click "Settings"
- Change visibility to "Public"
Check the Actions tab for detailed error logs:
https://github.com/<username>/<repo>/actions
Verify secrets are set correctly:
- Repository → Settings → Secrets and variables → Actions
- Check
DOCKERHUB_USERNAMEandDOCKERHUB_TOKENexist
For private images, authenticate first:
docker login docker.ioTypical build times (optimized for amd64 only):
- First build: 3-5 minutes
- Subsequent builds (with cache): 1-2 minutes
- Frontend and backend build stages run within a single image build
Optimizations applied:
- Single platform (amd64) instead of multi-platform
- npm ci with
--prefer-offlineand--no-auditflags - Disabled provenance and SBOM generation
- Latest BuildKit image
- GitHub Actions cache for Docker layers
- Secrets are never exposed in logs
- Images are scanned for vulnerabilities (optional - can add)
- Multi-stage builds minimize attack surface
- Non-root users in all containers
- Read-only root filesystems where possible
Frontend performance monitoring workflow.
See the workflow file for details.
To add a new workflow:
- Create a new YAML file in
.github/workflows/ - Use the GitHub Actions syntax
- Test locally with act (optional)
- Push to trigger the workflow