Use a minimal registry PAT and the job token for releases
CI / Backend tests (push) Successful in 2m23s
CI / Frontend build & lint (push) Successful in 22s

Gitea's container registry rejects the automatic job token
(go-gitea/gitea#23642 is still open), so the image push keeps a PAT with
only the write:package scope; a preflight step fails clearly when the
REGISTRY_USER/REGISTRY_TOKEN secrets are missing. Release creation needs
no PAT: the desktop job asks for contents: write on the job token.
This commit is contained in:
2026-09-22 23:35:55 -05:00
parent ed6178d12e
commit 7cecfeabc6
+17 -7
View File
@@ -11,8 +11,10 @@
# is still published with `deploy/push_desktop.sh --no-build` from a machine # is still published with `deploy/push_desktop.sh --no-build` from a machine
# that can reach it. # that can reach it.
# #
# Registry login uses the REGISTRY_USER / REGISTRY_TOKEN repo secrets. # Registry login uses a repo PAT with the minimal write:package scope (the
# Jobs run on the user-scoped nitro-ci runner (ubuntu-latest). # Gitea registry rejects the automatic job token, go-gitea/gitea#23642);
# release creation uses the automatic job token. Jobs run on the user-scoped
# nitro-ci runner (ubuntu-latest).
name: CD name: CD
@@ -36,20 +38,28 @@ jobs:
images: images:
name: Build & push images name: Build & push images
runs-on: ubuntu-latest runs-on: ubuntu-latest
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write` # The Gitea container registry does not accept the automatic job token
# also lets the automatic job token stand in when that secret is absent. # (go-gitea/gitea#23642 is still open), so the push uses a repo PAT with
# the minimal write:package scope. Releases use the job token instead.
permissions: permissions:
contents: read contents: read
packages: write
env: env:
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }} REGISTRY_USER: ${{ secrets.REGISTRY_USER }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }} REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }} PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Check the registry credentials
run: |
if [ -z "$REGISTRY_USER" ] || [ -z "$REGISTRY_TOKEN" ]; then
echo "Set the REGISTRY_USER and REGISTRY_TOKEN repo secrets" >&2
echo "(a PAT with the write:package scope)." >&2
exit 1
fi
- name: Register binfmt (multi-arch builds) - name: Register binfmt (multi-arch builds)
run: docker run --privileged --rm tonistiigi/binfmt --install all run: docker run --privileged --rm tonistiigi/binfmt --install all