diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 14c91f7..c4b4105 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -42,8 +42,8 @@ jobs: - uses: docker/login-action@v3 with: registry: git.rambossek.at - username: ${{ gitea.actor }} - password: ${{ secrets.GITEA_TOKEN }} + username: ${{ secrets.REGISTRY_USERNAME }} + password: ${{ secrets.REGISTRY_TOKEN }} - uses: docker/build-push-action@v6 with: diff --git a/README.md b/README.md index 0b92618..b831cb2 100644 --- a/README.md +++ b/README.md @@ -73,6 +73,10 @@ runs `go vet` and `go test -race`, and pushing a semantic-version tag `git.rambossek.at//gpu-turnstile:vX.Y.Z` (and updates `:latest`). No images are built from branches. +The registry login needs two repository secrets (Settings → Actions → +Secrets): `REGISTRY_USERNAME` and `REGISTRY_TOKEN` — an access token with +`write:package` scope. The automatic `GITEA_TOKEN` cannot push packages. + ## Development ```sh diff --git a/SPEC.md b/SPEC.md index 8061a48..0aed913 100644 --- a/SPEC.md +++ b/SPEC.md @@ -185,8 +185,10 @@ are new. available in the runner image 2. on a version tag only (`vX.Y.Z`, enforced): build the image with buildx and push it to the Gitea registry - `git.rambossek.at//gpu-turnstile` tagged `:` and `:latest`, - using the workflow token (`${{ secrets.GITEA_TOKEN }}` / `gitea.actor`) + `git.rambossek.at//gpu-turnstile` tagged `:` and `:latest`. + Login uses the repo secrets `REGISTRY_USERNAME` / `REGISTRY_TOKEN` (an + access token with `write:package` scope) because the automatic + `GITEA_TOKEN` cannot push packages. - Release: a git tag `vX.Y.Z` produces the versioned image; the Open WebUI compose pins that tag. No images are built from branches.