Use a minimal registry PAT and the job token for releases
Gitea's container registry rejects the automatic job token (go-gitea/gitea#23642 is still open), so the image push keeps a PAT with only the write:package scope; a preflight step fails clearly when the REGISTRY_USER/REGISTRY_TOKEN secrets are missing. Release creation needs no PAT: the desktop job asks for contents: write on the job token.
This commit is contained in:
+17
-7
@@ -11,8 +11,10 @@
|
|||||||
# is still published with `deploy/push_desktop.sh --no-build` from a machine
|
# is still published with `deploy/push_desktop.sh --no-build` from a machine
|
||||||
# that can reach it.
|
# that can reach it.
|
||||||
#
|
#
|
||||||
# Registry login uses the REGISTRY_USER / REGISTRY_TOKEN repo secrets.
|
# Registry login uses a repo PAT with the minimal write:package scope (the
|
||||||
# Jobs run on the user-scoped nitro-ci runner (ubuntu-latest).
|
# Gitea registry rejects the automatic job token, go-gitea/gitea#23642);
|
||||||
|
# release creation uses the automatic job token. Jobs run on the user-scoped
|
||||||
|
# nitro-ci runner (ubuntu-latest).
|
||||||
|
|
||||||
name: CD
|
name: CD
|
||||||
|
|
||||||
@@ -36,20 +38,28 @@ jobs:
|
|||||||
images:
|
images:
|
||||||
name: Build & push images
|
name: Build & push images
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write`
|
# The Gitea container registry does not accept the automatic job token
|
||||||
# also lets the automatic job token stand in when that secret is absent.
|
# (go-gitea/gitea#23642 is still open), so the push uses a repo PAT with
|
||||||
|
# the minimal write:package scope. Releases use the job token instead.
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
packages: write
|
|
||||||
env:
|
env:
|
||||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
REGISTRY_USER: ${{ secrets.REGISTRY_USER }}
|
||||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Check the registry credentials
|
||||||
|
run: |
|
||||||
|
if [ -z "$REGISTRY_USER" ] || [ -z "$REGISTRY_TOKEN" ]; then
|
||||||
|
echo "Set the REGISTRY_USER and REGISTRY_TOKEN repo secrets" >&2
|
||||||
|
echo "(a PAT with the write:package scope)." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Register binfmt (multi-arch builds)
|
- name: Register binfmt (multi-arch builds)
|
||||||
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user