From 7cecfeabc68fb786832d311c09c9031755190eaf Mon Sep 17 00:00:00 2001 From: JakeBreath Date: Tue, 22 Sep 2026 23:35:55 -0500 Subject: [PATCH] Use a minimal registry PAT and the job token for releases Gitea's container registry rejects the automatic job token (go-gitea/gitea#23642 is still open), so the image push keeps a PAT with only the write:package scope; a preflight step fails clearly when the REGISTRY_USER/REGISTRY_TOKEN secrets are missing. Release creation needs no PAT: the desktop job asks for contents: write on the job token. --- .gitea/workflows/cd.yml | 24 +++++++++++++++++------- 1 file changed, 17 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/cd.yml b/.gitea/workflows/cd.yml index cc6ab18..8d2205a 100644 --- a/.gitea/workflows/cd.yml +++ b/.gitea/workflows/cd.yml @@ -11,8 +11,10 @@ # is still published with `deploy/push_desktop.sh --no-build` from a machine # that can reach it. # -# Registry login uses the REGISTRY_USER / REGISTRY_TOKEN repo secrets. -# Jobs run on the user-scoped nitro-ci runner (ubuntu-latest). +# Registry login uses a repo PAT with the minimal write:package scope (the +# Gitea registry rejects the automatic job token, go-gitea/gitea#23642); +# release creation uses the automatic job token. Jobs run on the user-scoped +# nitro-ci runner (ubuntu-latest). name: CD @@ -36,20 +38,28 @@ jobs: images: name: Build & push images runs-on: ubuntu-latest - # Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write` - # also lets the automatic job token stand in when that secret is absent. + # The Gitea container registry does not accept the automatic job token + # (go-gitea/gitea#23642 is still open), so the push uses a repo PAT with + # the minimal write:package scope. Releases use the job token instead. permissions: contents: read - packages: write env: - REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }} - REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }} + REGISTRY_USER: ${{ secrets.REGISTRY_USER }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }} steps: - uses: actions/checkout@v4 with: fetch-depth: 0 + - name: Check the registry credentials + run: | + if [ -z "$REGISTRY_USER" ] || [ -z "$REGISTRY_TOKEN" ]; then + echo "Set the REGISTRY_USER and REGISTRY_TOKEN repo secrets" >&2 + echo "(a PAT with the write:package scope)." >&2 + exit 1 + fi + - name: Register binfmt (multi-arch builds) run: docker run --privileged --rm tonistiigi/binfmt --install all