forked from weaselab/conflict-set
Use a registry bot account for the container registry
Gitea's ephemeral Actions token is not accepted by the container registry, so docker login and image pulls use REGISTRY_USER / REGISTRY_TOKEN secrets (a dedicated low-privilege account and its personal access token with package read/write scope) instead.
This commit is contained in:
+11
-9
@@ -17,7 +17,9 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Log in to registry
|
||||
run: docker login -u ${{ gitea.actor }} -p ${{ secrets.GITHUB_TOKEN }} git.weaselab.dev
|
||||
run: |
|
||||
echo "${{ secrets.REGISTRY_TOKEN }}" \
|
||||
| docker login -u "${{ secrets.REGISTRY_USER }}" --password-stdin git.weaselab.dev
|
||||
|
||||
- name: Build and push image if changed
|
||||
run: |
|
||||
@@ -44,8 +46,8 @@ jobs:
|
||||
container:
|
||||
image: git.weaselab.dev/weaselab/conflict-set-ci:latest-amd64
|
||||
credentials:
|
||||
username: ${{ gitea.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
username: ${{ secrets.REGISTRY_USER }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
@@ -75,8 +77,8 @@ jobs:
|
||||
container:
|
||||
image: git.weaselab.dev/weaselab/conflict-set-ci:latest-amd64
|
||||
credentials:
|
||||
username: ${{ gitea.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
username: ${{ secrets.REGISTRY_USER }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
@@ -127,8 +129,8 @@ jobs:
|
||||
container:
|
||||
image: git.weaselab.dev/weaselab/conflict-set-ci:latest-${{ matrix.arch }}
|
||||
credentials:
|
||||
username: ${{ gitea.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
username: ${{ secrets.REGISTRY_USER }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
@@ -188,8 +190,8 @@ jobs:
|
||||
container:
|
||||
image: git.weaselab.dev/weaselab/conflict-set-ci:latest-amd64
|
||||
credentials:
|
||||
username: ${{ gitea.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
username: ${{ secrets.REGISTRY_USER }}
|
||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
|
||||
Reference in New Issue
Block a user