CI: log in to registry with REGISTRY_USERNAME/REGISTRY_TOKEN secrets
ci / test (push) Successful in 47s
ci / docker (push) Skipped

The automatic GITEA_TOKEN has no write:package scope, so docker login to
git.rambossek.at failed with unauthorized.
This commit is contained in:
mram
2026-09-20 18:24:54 +02:00
parent 5a0e181293
commit 73fb8ac3ad
3 changed files with 10 additions and 4 deletions
+2 -2
View File
@@ -42,8 +42,8 @@ jobs:
- uses: docker/login-action@v3
with:
registry: git.rambossek.at
username: ${{ gitea.actor }}
password: ${{ secrets.GITEA_TOKEN }}
username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_TOKEN }}
- uses: docker/build-push-action@v6
with:
+4
View File
@@ -73,6 +73,10 @@ runs `go vet` and `go test -race`, and pushing a semantic-version tag
`git.rambossek.at/<owner>/gpu-turnstile:vX.Y.Z` (and updates `:latest`).
No images are built from branches.
The registry login needs two repository secrets (Settings → Actions →
Secrets): `REGISTRY_USERNAME` and `REGISTRY_TOKEN` — an access token with
`write:package` scope. The automatic `GITEA_TOKEN` cannot push packages.
## Development
```sh
+4 -2
View File
@@ -185,8 +185,10 @@ are new.
available in the runner image
2. on a version tag only (`vX.Y.Z`, enforced): build the image with buildx
and push it to the Gitea registry
`git.rambossek.at/<owner>/gpu-turnstile` tagged `:<tag>` and `:latest`,
using the workflow token (`${{ secrets.GITEA_TOKEN }}` / `gitea.actor`)
`git.rambossek.at/<owner>/gpu-turnstile` tagged `:<tag>` and `:latest`.
Login uses the repo secrets `REGISTRY_USERNAME` / `REGISTRY_TOKEN` (an
access token with `write:package` scope) because the automatic
`GITEA_TOKEN` cannot push packages.
- Release: a git tag `vX.Y.Z` produces the versioned image; the Open WebUI
compose pins that tag. No images are built from branches.