Files
poimen-memory/REGISTRY_SETUP.md
T
rock c3f5f65540
CI / Test (pull_request) Successful in 2m8s
CI / Build & Push Image (pull_request) Skipped
fix: validate registry credentials before docker login
Problem: Registry login fails silently if secrets aren't configured
- Empty FORGEJO_REGISTRY_USER/TOKEN → docker login hangs/fails
- No clear error message about missing credentials

Solution: Add validation step that checks credentials exist
- Fails early with clear error if secrets missing
- Shows how to configure in repo settings
- Uses direct secret injection (not via env vars)
- Isolates docker config to /tmp/docker-config

Result: CI will fail fast with actionable error if credentials missing
2026-09-06 23:34:48 -07:00

2.3 KiB

Forgejo Registry Secrets Configuration

One-Time Setup (Org Level)

All repos in the rock org share the same Forgejo registry credentials.

Configure at Organization Level

  1. Navigate to: https://forgejo.riotpiao.com/rock
  2. Click Settings (gear icon)
  3. Go to: Actions → Secrets
  4. Add these org-level secrets:
    • Name: FORGEJO_REGISTRY_USER Value: rock

    • Name: FORGEJO_REGISTRY_TOKEN Value: <your-forgejo-token>

Get Your Forgejo Token

  1. Go to: https://forgejo.riotpiao.com/user/settings/applications
  2. Click "Generate New Token"
  3. Set scopes: api, read:registry, write:registry
  4. Copy the token value into the secret

Inheritance

Once org-level secrets are set:

  • All repos in rock org automatically inherit them
  • No per-repo configuration needed
  • Workflows reference via ${{ secrets.FORGEJO_REGISTRY_USER }}

Validation

Each repo's CI workflow includes a validation step:

- name: Validate registry credentials
  run: |
    if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then
      echo "❌ ERROR: Registry secrets not configured"
      echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in org settings"
      exit 1
    fi
    echo "✓ Registry credentials configured"

If secrets are missing, the validation step will fail with a clear error message pointing to this setup process.

Affected Repositories

The following repos use these shared org-level secrets in their CI workflows:

  • rock/riotpiao.com
  • rock/homelab-frontend
  • rock/poimen-workflows
  • rock/poimen-memory
  • rock/kmsvc-manage

All use the unified CI pattern:

  • test job: runs on all branches + PRs (no registry access)
  • build-push job: runs on main push only (requires registry credentials)

Troubleshooting

"Registry secrets not configured" error

If CI fails with this error:

  1. Check org settings: https://forgejo.riotpiao.com/rock/settings/actions/secrets
  2. Verify both secrets exist and are not empty
  3. Re-trigger the workflow by pushing to main

"unauthorized" from docker login

If you get error response from daemon: unauthorized:

  1. Check the token value is correct (copy-paste carefully)
  2. Verify token has read:registry and write:registry scopes
  3. Generate a new token if the old one expired