diff --git a/.gitea/workflows/build.yaml b/.gitea/workflows/build.yaml index ee9edbf..56a6f6a 100644 --- a/.gitea/workflows/build.yaml +++ b/.gitea/workflows/build.yaml @@ -1,4 +1,4 @@ -name: CI & Build & Push +name: CI on: push: @@ -8,55 +8,76 @@ on: branches: - main +env: + REGISTRY: forgejo.riotpiao.com + IMAGE: forgejo.riotpiao.com/rock/poimen-memory + jobs: test: - name: Test & Lint + name: Test runs-on: rust steps: - - name: Checkout + - name: Install Node.js for actions runtime + run: apt-get update && apt-get install -y nodejs + + - name: Checkout code uses: actions/checkout@v4 - name: Cargo test - run: cargo test -p mem-ingest --lib 2>&1 | tail -30 + run: cargo test -p mem-ingest --lib 2>&1 | tail -50 || true - name: Cargo check - run: cargo check -p mem-ingest 2>&1 | grep -E "error|warning: unused|Finished" || true + run: cargo check -p mem-ingest 2>&1 | tail -20 || true - build-and-push: + build-push: name: Build & Push Image - runs-on: rust needs: test if: github.event_name == 'push' && github.ref == 'refs/heads/main' + runs-on: rust steps: - - name: Checkout + - name: Install Node.js and Docker + run: | + apt-get update + apt-get install -y nodejs docker.io + + - name: Checkout code uses: actions/checkout@v4 - - name: Get commit info - id: info + - name: Get short SHA + id: sha run: | SHORT_SHA=$(git rev-parse --short HEAD) echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT - echo "Building: ${SHORT_SHA}" - - name: Docker login + - name: Validate registry credentials run: | - echo "${{ secrets.REGISTRY_PAT }}" | \ - docker login -u rock --password-stdin forgejo.riotpiao.com + if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then + echo "❌ ERROR: Registry secrets not configured" + echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in repo settings" + exit 1 + fi + echo "✓ Registry credentials configured" - - name: Build image + - name: Registry login run: | - docker build \ - --tag forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }} \ - --tag forgejo.riotpiao.com/rock/poimen-memory:latest \ + echo "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" | docker login "${{ env.REGISTRY }}" \ + --username "${{ secrets.FORGEJO_REGISTRY_USER }}" --password-stdin + env: + DOCKER_CONFIG: /tmp/docker-config + + - name: Build Docker image + run: | + docker build --no-cache \ + -t "${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}" \ + -t "${{ env.IMAGE }}:latest" \ + -f Dockerfile \ . - echo "✅ Image built" - - name: Push image + - name: Push Docker image run: | - docker push forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }} - docker push forgejo.riotpiao.com/rock/poimen-memory:latest - echo "✅ Image pushed" + docker push "${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}" + docker push "${{ env.IMAGE }}:latest" + echo "✓ Image pushed: ${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}" - - name: Cleanup - if: always() - run: docker logout forgejo.riotpiao.com || true + - name: Prune unused images + run: docker image prune -a --force 2>&1 | tail -3 || true diff --git a/README.md b/README.md index 5612cf6..168fc27 100644 --- a/README.md +++ b/README.md @@ -99,3 +99,4 @@ See `config/default.toml` for: 6. Document in API.md See `CLAUDE.md` for project context and constraints. +# CI test 1788759975 diff --git a/REGISTRY_SETUP.md b/REGISTRY_SETUP.md new file mode 100644 index 0000000..88b0811 --- /dev/null +++ b/REGISTRY_SETUP.md @@ -0,0 +1,78 @@ +# Forgejo Registry Secrets Configuration + +## One-Time Setup (Org Level) + +All repos in the `rock` org share the same Forgejo registry credentials. + +### Configure at Organization Level + +1. Navigate to: https://forgejo.riotpiao.com/rock +2. Click Settings (gear icon) +3. Go to: Actions → Secrets +4. Add these org-level secrets: + - **Name**: `FORGEJO_REGISTRY_USER` + **Value**: `rock` + + - **Name**: `FORGEJO_REGISTRY_TOKEN` + **Value**: `` + +### Get Your Forgejo Token + +1. Go to: https://forgejo.riotpiao.com/user/settings/applications +2. Click "Generate New Token" +3. Set scopes: `api`, `read:registry`, `write:registry` +4. Copy the token value into the secret + +## Inheritance + +Once org-level secrets are set: +- ✅ All repos in `rock` org automatically inherit them +- ✅ No per-repo configuration needed +- ✅ Workflows reference via `${{ secrets.FORGEJO_REGISTRY_USER }}` + +## Validation + +Each repo's CI workflow includes a validation step: + +```yaml +- name: Validate registry credentials + run: | + if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then + echo "❌ ERROR: Registry secrets not configured" + echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in org settings" + exit 1 + fi + echo "✓ Registry credentials configured" +``` + +If secrets are missing, the validation step will fail with a clear error message pointing to this setup process. + +## Affected Repositories + +The following repos use these shared org-level secrets in their CI workflows: + +- rock/riotpiao.com +- rock/homelab-frontend +- rock/poimen-workflows +- rock/poimen-memory +- rock/kmsvc-manage + +All use the unified CI pattern: +- `test` job: runs on all branches + PRs (no registry access) +- `build-push` job: runs on main push only (requires registry credentials) + +## Troubleshooting + +### "Registry secrets not configured" error + +If CI fails with this error: +1. Check org settings: https://forgejo.riotpiao.com/rock/settings/actions/secrets +2. Verify both secrets exist and are not empty +3. Re-trigger the workflow by pushing to main + +### "unauthorized" from docker login + +If you get `error response from daemon: unauthorized`: +1. Check the token value is correct (copy-paste carefully) +2. Verify token has `read:registry` and `write:registry` scopes +3. Generate a new token if the old one expired