Use a minimal registry PAT and the job token for releases
Gitea's container registry rejects the automatic job token (go-gitea/gitea#23642 is still open), so the image push keeps a PAT with only the write:package scope; a preflight step fails clearly when the REGISTRY_USER/REGISTRY_TOKEN secrets are missing. Release creation needs no PAT: the desktop job asks for contents: write on the job token.
This commit is contained in:
+17
-7
@@ -11,8 +11,10 @@
|
||||
# is still published with `deploy/push_desktop.sh --no-build` from a machine
|
||||
# that can reach it.
|
||||
#
|
||||
# Registry login uses the REGISTRY_USER / REGISTRY_TOKEN repo secrets.
|
||||
# Jobs run on the user-scoped nitro-ci runner (ubuntu-latest).
|
||||
# Registry login uses a repo PAT with the minimal write:package scope (the
|
||||
# Gitea registry rejects the automatic job token, go-gitea/gitea#23642);
|
||||
# release creation uses the automatic job token. Jobs run on the user-scoped
|
||||
# nitro-ci runner (ubuntu-latest).
|
||||
|
||||
name: CD
|
||||
|
||||
@@ -36,20 +38,28 @@ jobs:
|
||||
images:
|
||||
name: Build & push images
|
||||
runs-on: ubuntu-latest
|
||||
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write`
|
||||
# also lets the automatic job token stand in when that secret is absent.
|
||||
# The Gitea container registry does not accept the automatic job token
|
||||
# (go-gitea/gitea#23642 is still open), so the push uses a repo PAT with
|
||||
# the minimal write:package scope. Releases use the job token instead.
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
env:
|
||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Check the registry credentials
|
||||
run: |
|
||||
if [ -z "$REGISTRY_USER" ] || [ -z "$REGISTRY_TOKEN" ]; then
|
||||
echo "Set the REGISTRY_USER and REGISTRY_TOKEN repo secrets" >&2
|
||||
echo "(a PAT with the write:package scope)." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Register binfmt (multi-arch builds)
|
||||
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
||||
|
||||
|
||||
Reference in New Issue
Block a user