Gitea's container registry rejects the automatic job token (go-gitea/gitea#23642 is still open), so the image push keeps a PAT with only the write:package scope; a preflight step fails clearly when the REGISTRY_USER/REGISTRY_TOKEN secrets are missing. Release creation needs no PAT: the desktop job asks for contents: write on the job token.