Fix CI for the user-scoped runners

- ci.yml: connect to the test MariaDB as root so Django creates the test
  database itself (no client install/grant step), and drop actions/cache
  (cache: pip/npm): Gitea's cache service hangs the job on restore/save.
- publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other
  repos) and fall back to the automatic Actions token.
- AGENTS.md: note the CI layout, the runner labels and the cache caveat.
This commit is contained in:
2026-09-22 23:12:56 -05:00
parent d9c1e9e521
commit 72fc42217f
3 changed files with 28 additions and 33 deletions
+12 -1
View File
@@ -49,6 +49,12 @@ Project constraints (do not regress):
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
refresh) run in the composes' `scheduler` service — the backend image with
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
the full backend suite against MariaDB/Redis service containers, frontend
lint/type-check/build); publish.yml is manual and builds/pushes both images
multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
`desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
to these workflows: Gitea's cache service hangs the job on restore/save.
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
@@ -85,7 +91,12 @@ Security hardening (do not weaken):
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
(and all signed media URLs), so users must re-enter the key.
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
on purpose: <img>/<video> tags fetch them without an Authorization header,
so a gallery would otherwise drain the anonymous bucket and get 429 JSON
instead of images. THROTTLE_ENABLED=false removes the anon+user limits for
private/tailnet deployments (the login/register/proxy guards stay).
- Only admins (superusers) may grant/revoke the staff role or delete
staff/admin accounts; staff manage regular/uploader accounts only.
- Storage, duplicates, delete, temp-clear, uploads and downloads require