nais/GAR build/push/sign

Build, push, and sign (to Google Artifact Registry and optionally to GHCR)

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 3, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: nais/platform-build-push-sign@07a21e2293624a78499c79eeea3ce6d314f8a8d9 # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
dockerfileDockerfile pathDockerfile
nameName of imageyes
google_service_accountName of google service account to impersonateno
pushWhether or not to push imagetrue
push_ghcrWhether or not to push image to GHCRfalse
workload_identity_providerThe workload identity provider for google service account impersonationno
registryThe Google Artifact Registry path to push image toeurope-north1-docker.pkg.dev/nais-io/nais/images
build_argsList of build argsno
build_secretsList of secretsno
sbomexisting SBOM in cyclonedx formatauto-generate-for-me-please.json
additional_sbomsNewline-separated list of extra CycloneDX SBOM files to merge with the primary SBOMno""
extra_tagsA list of tags to be applied in addition to the detailed time+sha-tag and latest-tag""
multi-platformBuild multi-platform images, supporting amd64 and arm64false
contextDocker build context.
cache_fromcache-from sent to docker/build-push-actiontype=gha
cache_tocache-to sent to docker/build-push-actiontype=gha,mode=max
targetdocker targetno
namedescription
tagfull image tag
versionversion
imageCanonical image reference
digestImage digest