Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 2117043e31 | |||
| 84c47136df | |||
| 23ad9ebc32 |
@@ -13,6 +13,11 @@ jobs:
|
||||
# regardless of this instance's default Actions permission mode.
|
||||
permissions:
|
||||
contents: write
|
||||
# Runner defaults `run:` steps to `sh`, which doesn't understand
|
||||
# `set -o pipefail` used below — force bash explicitly.
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
# Must match a label your act_runner is registered with. The runner's
|
||||
# own default label-image is irrelevant here since `container:` below
|
||||
# overrides the actual build image per-job.
|
||||
@@ -22,6 +27,11 @@ jobs:
|
||||
# Pin to a specific tag here (see build-image/VERSION) if you need a
|
||||
# release build to be reproducible against an exact toolchain image.
|
||||
image: cr.ladkau.de/schwert-und-magie/builder:latest
|
||||
# Lets the runner pull a private image without a manual `docker login`
|
||||
# on the runner host — see docs/publish.md §4.3.
|
||||
credentials:
|
||||
username: ${{ secrets.REGISTRY_USER }}
|
||||
password: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
@@ -159,6 +159,7 @@ publishes a Gitea Release with the versioned artifacts attached — see
|
||||
|---|---|
|
||||
| `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` |
|
||||
| `RELEASE_KEYSTORE_PROPERTIES` | full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` |
|
||||
| `REGISTRY_USER` / `REGISTRY_PASSWORD` | same as in `registry.env`, so the runner can pull the private build image |
|
||||
|
||||
`GITEA_TOKEN` is injected automatically per job — nothing to add for it.
|
||||
4. `git tag v1.2.3 && git push origin v1.2.3`.
|
||||
|
||||
@@ -42,7 +42,11 @@ fi
|
||||
if [ ! -d "${SRC}" ]; then
|
||||
echo "Unpacking nibtools..."
|
||||
tar -xzf "${TARBALL}" -C "${SCRIPT_DIR}"
|
||||
mv "${SCRIPT_DIR}"/nibtools-*/ "${SRC}"
|
||||
# Hardcoded, not a glob: on a non-ephemeral runner workspace, a
|
||||
# nibtools-*/ glob can also match SRC itself once it exists, or other
|
||||
# stray nibtools-prefixed leftovers, and mv then fails with "target is
|
||||
# not a directory" (multiple sources, no existing target dir).
|
||||
mv "${SCRIPT_DIR}/nibtools-91344e0ee3" "${SRC}"
|
||||
echo "Unpacked to ${SRC}"
|
||||
fi
|
||||
|
||||
|
||||
+6
-3
@@ -296,9 +296,10 @@ line in `.gitea/workflows/release.yml` to the versioned tag instead.
|
||||
in `.gitea/workflows/release.yml` — edit both together if you rename it,
|
||||
or reuse a label an existing runner already advertises (check Site Admin →
|
||||
Actions → Runners) to skip registering a new one entirely.
|
||||
4. The runner's Docker daemon needs pull access to the registry — run
|
||||
`docker login <registry>` once on that machine with the same credentials
|
||||
as `registry.env`.
|
||||
|
||||
No manual `docker login` needed on the runner host — the workflow's
|
||||
`container:` block authenticates the image pull itself via the
|
||||
`REGISTRY_USER`/`REGISTRY_PASSWORD` secrets (§4.3).
|
||||
|
||||
### 4.3 Repo secrets
|
||||
|
||||
@@ -308,6 +309,8 @@ Settings → Actions → Secrets, add:
|
||||
|---|---|
|
||||
| `RELEASE_KEYSTORE_B64` | `base64 -w0 SchwertUndMagieOnPebbleCompanionApp/release.keystore` |
|
||||
| `RELEASE_KEYSTORE_PROPERTIES` | the full contents of `SchwertUndMagieOnPebbleCompanionApp/keystore.properties` (§2.2) |
|
||||
| `REGISTRY_USER` | same as `REGISTRY_USER` in `registry.env` |
|
||||
| `REGISTRY_PASSWORD` | same as `REGISTRY_PASSWORD` in `registry.env` |
|
||||
|
||||
`secrets.GITEA_TOKEN` (used to create the release and upload assets) is
|
||||
Gitea's own auto-generated per-job token — nothing to create or add yourself.
|
||||
|
||||
Reference in New Issue
Block a user