2 Commits
Author SHA1 Message Date
rockandAdmin Bot 1cd8e711dd ci: unified workflow - single job, DOCKER_HOST, build+push on all events (#4)
CI / CI (push) Successful in 3m23s
- Single job (no split test/build-push)
- DOCKER_HOST=tcp://localhost:2375 for dind
- Build + push on PRs too (verify before merge)
- workflow_dispatch for manual trigger

---------

Co-authored-by: Admin Bot <[email protected]>
Reviewed-on: #4
2026-09-07 21:01:02 +00:00
rockandAdmin Bot 736c0d7724 fix: use env vars for docker registry credentials (#2)
CI / Test (push) Successful in 1m51s
CI / Build & Push Image (push) Failing after 1m6s
Fix registry login by passing FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN via environment variables instead of direct secret interpolation.

Uses the proven pattern from riotpiao.com reference commit.

This prevents credentials from being exposed in logs or shell history while keeping the standard docker login approach.

After merge + org-level secrets configured:
- All repos inherit FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN
- CI validates credentials exist before docker login
- Image pushed to registry on main push

---------

Co-authored-by: Admin Bot <[email protected]>
Reviewed-on: #2
2026-09-07 06:50:48 +00:00
2 changed files with 14 additions and 105 deletions
+14 -27
View File
@@ -5,32 +5,16 @@ on:
branches: [main] branches: [main]
pull_request: pull_request:
branches: [main] branches: [main]
workflow_dispatch:
env: env:
REGISTRY: forgejo.riotpiao.com REGISTRY: forgejo.riotpiao.com
IMAGE: forgejo.riotpiao.com/rock/homelab-frontend IMAGE: forgejo.riotpiao.com/rock/api-gateway
DOCKER_HOST: tcp://localhost:2375
jobs: jobs:
test: ci:
name: Test name: CI
runs-on: golang
steps:
- name: Install Node.js for actions runtime
run: apt-get update && apt-get install -y nodejs
- name: Checkout code
uses: actions/checkout@v4
- name: Go vet
run: go vet ./...
- name: Go test
run: go test ./...
build-push:
name: Build & Push Image
needs: test
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: golang runs-on: golang
steps: steps:
- name: Install Node.js and Docker - name: Install Node.js and Docker
@@ -41,11 +25,15 @@ jobs:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Go vet
run: go vet ./...
- name: Go test
run: go test ./...
- name: Get short SHA - name: Get short SHA
id: sha id: sha
run: | run: echo "short_sha=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT
SHORT_SHA=$(git rev-parse --short HEAD)
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Registry login - name: Registry login
run: | run: |
@@ -60,14 +48,13 @@ jobs:
docker build --no-cache \ docker build --no-cache \
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
-t "${IMAGE}:latest" \ -t "${IMAGE}:latest" \
-f Dockerfile \ -f Dockerfile .
.
- name: Push Docker image - name: Push Docker image
run: | run: |
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:latest" docker push "${IMAGE}:latest"
echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" echo "✓ Pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
- name: Prune unused images - name: Prune unused images
run: docker image prune -a --force 2>&1 | tail -3 || true run: docker image prune -a --force 2>&1 | tail -3 || true
-78
View File
@@ -1,78 +0,0 @@
# Forgejo Registry Secrets Configuration
## One-Time Setup (Org Level)
All repos in the `rock` org share the same Forgejo registry credentials.
### Configure at Organization Level
1. Navigate to: https://forgejo.riotpiao.com/rock
2. Click Settings (gear icon)
3. Go to: Actions → Secrets
4. Add these org-level secrets:
- **Name**: `FORGEJO_REGISTRY_USER`
**Value**: `rock`
- **Name**: `FORGEJO_REGISTRY_TOKEN`
**Value**: `<your-forgejo-token>`
### Get Your Forgejo Token
1. Go to: https://forgejo.riotpiao.com/user/settings/applications
2. Click "Generate New Token"
3. Set scopes: `api`, `read:registry`, `write:registry`
4. Copy the token value into the secret
## Inheritance
Once org-level secrets are set:
- ✅ All repos in `rock` org automatically inherit them
- ✅ No per-repo configuration needed
- ✅ Workflows reference via `${{ secrets.FORGEJO_REGISTRY_USER }}`
## Validation
Each repo's CI workflow includes a validation step:
```yaml
- name: Validate registry credentials
run: |
if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then
echo "❌ ERROR: Registry secrets not configured"
echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in org settings"
exit 1
fi
echo "✓ Registry credentials configured"
```
If secrets are missing, the validation step will fail with a clear error message pointing to this setup process.
## Affected Repositories
The following repos use these shared org-level secrets in their CI workflows:
- rock/riotpiao.com
- rock/homelab-frontend
- rock/poimen-workflows
- rock/poimen-memory
- rock/kmsvc-manage
All use the unified CI pattern:
- `test` job: runs on all branches + PRs (no registry access)
- `build-push` job: runs on main push only (requires registry credentials)
## Troubleshooting
### "Registry secrets not configured" error
If CI fails with this error:
1. Check org settings: https://forgejo.riotpiao.com/rock/settings/actions/secrets
2. Verify both secrets exist and are not empty
3. Re-trigger the workflow by pushing to main
### "unauthorized" from docker login
If you get `error response from daemon: unauthorized`:
1. Check the token value is correct (copy-paste carefully)
2. Verify token has `read:registry` and `write:registry` scopes
3. Generate a new token if the old one expired