
如果你使用 DeepSeek、元宝 AI、Copilot、ChatGPT 等 AI 工具,协助配置轩辕镜像、编写 docker pull 命令、修改 Docker Compose 镜像地址、配置镜像加速、排查镜像拉取失败、分析报错日志等问题,请先让 AI 阅读并遵守轩辕镜像的规则文档。
只需在 AI 对话中先发送下面这段话即可:
请先阅读并遵守:https://xuanyuan.cloud/agents.md
未读文档前不要生成 pull 命令或排错方案。查看 agents.md 用法指南与完整示范。国内用户首推 元宝 AI、DeepSeek 的深度思考模式,不推荐豆包 AI;Cursor 等编辑器可在对话 @ 该链接,或加入 User Rules。 若 AI 无法访问外链,可 打开说明文档 复制全文粘贴。文档会随站点更新,复制内容可能过期,建议定期检查。
用于在CI中运行Google Container Structure Tests的GitHub Action镜像
docker、tar和host驱动{{VAR_NAME}}占位符linux/amd64和linux/arm64查看DevOps-Infra的其他Action
https://github.com/devops-infra/action-container-structure-test "shields.io"
https://hub.docker.com/r/devopsinfra/action-container-structure-test "shields.io"
该Action支持三种标签级别以实现灵活版本控制:
vX:主版本的最新补丁(如v1)vX.Y:次版本的最新补丁(如v1.0)vX.Y.Z:固定到特定版本(如v1.0.0)yaml- name: 运行Action uses: devops-infra/action-container-structure-test@v1.0.7 with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml driver: docker output: text debug: false
| 输入参数 | 是否必填 | 默认值 | 描述 |
|---|---|---|---|
image | * | 待测试镜像。除非设置image_from_oci_layout,否则必填。与后者互斥。 | |
config | 是 | 测试配置文件路径。多个文件用空格或换行分隔。{{VAR_NAME}}占位符从作业环境渲染。 | |
driver | 否 | docker | 运行测试时使用的驱动:docker、tar或host。 |
platform | 否 | 测试平台,如linux/amd64或linux/arm64。默认与主机架构一致。 | |
pull | 否 | false | 运行测试前强制拉取镜像(仅docker驱动)。 |
save | 否 | false | 测试后保留创建的容器。 |
quiet | 否 | false | 抑制测试输出。 |
no_color | 否 | false | 禁用彩色输出。 |
output | 否 | text | 输出格式:text、json或junit。 |
test_report | 否 | 将测试结果写入该文件路径,然后打印到日志。CST自动将text转换为json。 | |
junit_suite_name | 否 | JUnit测试套件名称(仅当output为junit时使用)。 | |
metadata | 否 | 镜像元数据文件路径。 | |
runtime | 否 | docker驱动使用的运行时(如gVisor的runsc)。 | |
force | 否 | false | 强制运行host驱动,无需交互提示。 |
image_from_oci_layout | 否 | OCI镜像布局目录路径。与image互斥。 | |
default_image_tag | 否 | OCI布局缺少ref注释时的默认镜像标签。需设置image_from_oci_layout。 | |
ignore_ref_annotation | 否 | false | 加载OCI布局时忽略org.opencontainers.image.ref.name注释。 |
debug | 否 | false | 启用Action入口点的详细调试日志。 |
| 输出参数 | 描述 |
|---|---|
total | 执行的测试总数。 |
passed | 通过的测试数量。 |
failed | 失败的测试数量。 |
exit_code | container-structure-test返回的退出码。 |
使用单个配置文件对Docker镜像运行结构测试。
yamlname: 每次提交运行结构测试 on: [push] jobs: container-structure-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: 构建镜像 run: docker build -t my-image:latest . - uses: devops-infra/action-container-structure-test@v1 with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml
使用多个配置文件、JSON输出和保存报告运行测试。
yamlname: 每次提交运行结构测试 on: [push] jobs: container-structure-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: 构建镜像 run: docker build -t my-image:latest . - name: 运行结构测试 id: cst uses: devops-infra/action-container-structure-test@v1 with: image: docker.xuanyuan.run/my-image:latest config: | tests/command-tests.yaml tests/file-tests.yaml output: json test_report: /tmp/cst-report.json pull: 'false' debug: 'false' - name: 显示测试结果 run: | echo "Total: ${{ steps.cst.outputs.total }}" echo "Passed: ${{ steps.cst.outputs.passed }}" echo "Failed: ${{ steps.cst.outputs.failed }}" echo "Exit: ${{ steps.cst.outputs.exit_code }}"
根据稳定性需求选择标签级别:
vX.Y.Z:精确不可变版本(最可预测)vX.Y:次版本内的最新补丁vX:主版本内的最新补丁yamlname: 每次提交运行结构测试 on: [push] jobs: container-structure-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - uses: devops-infra/action-container-structure-test@v1.0.7 id: pin-patch-version with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml - uses: devops-infra/action-container-structure-test@v1.0 id: pin-minor-version with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml - uses: devops-infra/action-container-structure-test@v1 id: pin-major-version with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml
生成JUnit报告用于测试结果发布。
yamlname: 每次提交运行结构测试 on: [push] jobs: container-structure-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: 构建镜像 run: docker build -t my-image:latest . - name: 运行结构测试 uses: devops-infra/action-container-structure-test@v1 with: image: docker.xuanyuan.run/my-image:latest config: tests/structure-test.yaml output: junit junit_suite_name: container-structure-tests test_report: /tmp/cst-results.xml
无需Docker守护进程测试导出的镜像(仅文件/元数据测试)。
yamlname: 每次提交运行结构测试 on: [push] jobs: container-structure-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: 导出镜像为tar run: docker save my-image:latest -o my-image.tar - uses: devops-infra/action-container-structure-test@v1 with: image: my-image.tar config: tests/file-tests.yaml driver: tar
Container Structure Test配置为YAML或JSON文件。当前 schema版本为2.0.0,必须在每个配置中设置。
Action在调用CST前会渲染配置文件中的{{VAR_NAME}}占位符。用于工作流控制的值(如导出到GITHUB_ENV的版本)可使用此功能。容器内的shell扩展应保留${VAR}语法。
示例:
yamlcommandTests: - name: Azure CLI command: bash args: - -lc - test "$(az version --output json | jq -r '."azure-cli"')" = '{{AZ_VERSION}}'
yamlschemaVersion: '2.0.0' commandTests: - name: "python版本" command: "python3" args: ["--version"] expectedOutput: ["Python 3\\..*"] fileExistenceTests: - name: "入口点存在" path: "/entrypoint.sh" shouldExist: true permissions: "-rwxr-xr-x" fileContentTests: - name: "源列表" path: "/etc/os-release" expectedContents: [".*alpine.*"] metadataTest: workdir: "/app" envVars: - key: PATH value: "/usr/local/bin:.*" isRegex: true
完整文档:https://github.com/GoogleContainerTools/container-structure-test
包含的工作流:
.github/workflows/auto-pull-request-create.yml)
master和dependabot/**外的任何分支.github/workflows/auto-create-release.yml)
pull_request关闭且推送到release/**(仅从release/合并的PR运行)vX.Y.Z;更新vX.Y和vX(如果远程存在完整标签则失败).github/workflows/cron-dependency-update.yml)
.github/workflows/manual-release-branch-prepare.yml)
workflow_dispatch,需提供type(patch|minor|major|set)或type=set时的versionrelease/vX.Y.Z,构建/推送-rc镜像,并打开版本PR.github/workflows/auto-release-create.yml,打标签并发布最终版本REL_VERSION您可以使用以下命令拉取该镜像。请将 <标签> 替换为具体的标签版本。如需查看所有可用标签版本,请访问 标签列表页面。
来自真实用户的反馈,见证轩辕镜像的优质服务