Adding container registry login for gitea action
release / build (push) Failing after 52s

This commit is contained in:
ml
2026-07-02 13:57:35 +02:00
parent f3f7442849
commit 23ad9ebc32
3 changed files with 12 additions and 3 deletions
+5
View File
@@ -22,6 +22,11 @@ jobs:
# Pin to a specific tag here (see build-image/VERSION) if you need a # Pin to a specific tag here (see build-image/VERSION) if you need a
# release build to be reproducible against an exact toolchain image. # release build to be reproducible against an exact toolchain image.
image: cr.ladkau.de/schwert-und-magie/builder:latest image: cr.ladkau.de/schwert-und-magie/builder:latest
# Lets the runner pull a private image without a manual `docker login`
# on the runner host — see docs/publish.md §4.3.
credentials:
username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
+1
View File
@@ -159,6 +159,7 @@ publishes a Gitea Release with the versioned artifacts attached — see
|---|---| |---|---|
| `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` | | `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` |
| `RELEASE_KEYSTORE_PROPERTIES` | full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` | | `RELEASE_KEYSTORE_PROPERTIES` | full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` |
| `REGISTRY_USER` / `REGISTRY_PASSWORD` | same as in `registry.env`, so the runner can pull the private build image |
`GITEA_TOKEN` is injected automatically per job — nothing to add for it. `GITEA_TOKEN` is injected automatically per job — nothing to add for it.
4. `git tag v1.2.3 && git push origin v1.2.3`. 4. `git tag v1.2.3 && git push origin v1.2.3`.
+6 -3
View File
@@ -296,9 +296,10 @@ line in `.gitea/workflows/release.yml` to the versioned tag instead.
in `.gitea/workflows/release.yml` — edit both together if you rename it, in `.gitea/workflows/release.yml` — edit both together if you rename it,
or reuse a label an existing runner already advertises (check Site Admin → or reuse a label an existing runner already advertises (check Site Admin →
Actions → Runners) to skip registering a new one entirely. Actions → Runners) to skip registering a new one entirely.
4. The runner's Docker daemon needs pull access to the registry — run
`docker login <registry>` once on that machine with the same credentials No manual `docker login` needed on the runner host — the workflow's
as `registry.env`. `container:` block authenticates the image pull itself via the
`REGISTRY_USER`/`REGISTRY_PASSWORD` secrets (§4.3).
### 4.3 Repo secrets ### 4.3 Repo secrets
@@ -308,6 +309,8 @@ Settings → Actions → Secrets, add:
|---|---| |---|---|
| `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` | | `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` |
| `RELEASE_KEYSTORE_PROPERTIES` | the full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` (§2.2) | | `RELEASE_KEYSTORE_PROPERTIES` | the full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` (§2.2) |
| `REGISTRY_USER` | same as `REGISTRY_USER` in `registry.env` |
| `REGISTRY_PASSWORD` | same as `REGISTRY_PASSWORD` in `registry.env` |
`secrets.GITEA_TOKEN` (used to create the release and upload assets) is `secrets.GITEA_TOKEN` (used to create the release and upload assets) is
Gitea's own auto-generated per-job token — nothing to create or add yourself. Gitea's own auto-generated per-job token — nothing to create or add yourself.