Build and push the Docker image to the Forgejo registry on main #14
Loading…
Reference in a new issue
No description provided.
Delete branch "cc-7-deploy"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds a
deployjob to CI. On a push tomain, aftercheckpasses, it builds the image and pusheslatestand the commit SHA togit.robware.uk/rob/campercan.compose.yamlnow pulls that image instead of building, and the README "Run it" section says how to pull on the host or build locally.Login uses
secrets.REGISTRY_TOKENif set, elsesecrets.GITHUB_TOKEN. The PlaceMark workflow notes thatGITHUB_TOKENauthenticates but is refused on push (no package scope). If the first push tomainfails with a 401, the owner needs to add aREGISTRY_TOKENrepo secret (a token with write:package).Testing: none possible. CI on this PR only runs
check;deployis skipped until the merge tomain. Docker is known to work on the runner (PlaceMark builds and pushes images there).Ticket: CC-7.
Scope: the branch carries a lot that isn't CC-7. Drop these from the PR (rebase onto site-hardening or split out):
Findings in the deploy change:
-u ${{ github.actor }}is whoever pushed or merged. If REGISTRY_TOKEN is a PAT it belongs to one user, so login fails when anyone else merges. Use a fixed username (rob), and pass it via env rather than inline interpolation.|| secrets.GITHUB_TOKENfallback may not have package:write on this Forgejo, so the push could 401. Not verified. Either confirm it works or require REGISTRY_TOKEN and fail fast if it's empty.concurrencyhas cancel-in-progress: true. A second push to main during the deploy cancels it mid-push, which can leavelatestand the SHA tag out of step. Give deploy its own non-cancelling group.env:(e.g.IMAGE) and reuse it.Review follow-up in
72fe9f5. Finding 1 (scope): the PR diff is only ci.yml, README.md and compose.yaml; the other files were a stale base comparison, no change. Findings 2 and 4 fixed: login uses the repository owner, and main runs are no longer cancelled. Finding 3 and 6: known, the REGISTRY_TOKEN fallback is documented in the PR body and ticket; the first push to main will show it. Finding 5 left as is.