Add the manual CD release workflow

One dispatch builds and pushes both images and builds the desktop packages
into a Gitea release (desktop-v<version>, installers + latest*.yml attached,
idempotent on re-run). The live update feed stays a deploy-host operation:
CI has no SSH key for jakerasp, so push_desktop.sh --no-build remains the
way to publish it.

Repo secrets REGISTRY_USER/REGISTRY_TOKEN are set, so the image push uses
the Gitea registry credentials directly.
This commit is contained in:
2026-09-22 23:23:05 -05:00
parent 72fc42217f
commit 8f9656ac0e
4 changed files with 164 additions and 59 deletions
+10 -6
View File
@@ -49,12 +49,16 @@ Project constraints (do not regress):
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
refresh) run in the composes' `scheduler` service — the backend image with
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
the full backend suite against MariaDB/Redis service containers, frontend
lint/type-check/build); publish.yml is manual and builds/pushes both images
multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
`desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
to these workflows: Gitea's cache service hangs the job on restore/save.
- CI/CD lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks
+ the full backend suite against MariaDB/Redis service containers, frontend
lint/type-check/build); cd.yml is manual and builds/pushes both images
multi-arch plus the desktop packages (attached to the Gitea release
`desktop-v<version>`). Jobs run on the user-scoped runners: `ubuntu-latest`
on nitro-ci, `desktop` on msi-mortar-ci. Do not add actions/cache
(`cache: pip`/`npm`) to these workflows: Gitea's cache service hangs the job
on restore/save. The live desktop update feed (deploy/data/desktop) is still
published with `deploy/push_desktop.sh --no-build` from a machine with SSH
to the deploy host — CI has no key for that.
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';