fix: use env vars for docker registry credentials
Pass FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN via environment variables instead of direct secret interpolation. This is the standard approach used across all repos and prevents credentials from being exposed in logs or shell history. Fixes registry login failures by using the proven pattern.
This commit is contained in:
@@ -41,18 +41,14 @@ jobs:
|
|||||||
runs-on: golang
|
runs-on: golang
|
||||||
steps:
|
steps:
|
||||||
- name: Install Node.js and Docker
|
- name: Install Node.js and Docker
|
||||||
run: |
|
run: apt-get update && apt-get install -y nodejs docker.io
|
||||||
apt-get update
|
|
||||||
apt-get install -y nodejs docker.io
|
|
||||||
|
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Get short SHA
|
- name: Get short SHA
|
||||||
id: sha
|
id: sha
|
||||||
run: |
|
run: echo "short_sha=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT
|
||||||
SHORT_SHA=$(git rev-parse --short HEAD)
|
|
||||||
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
|
|
||||||
|
|
||||||
- name: Registry login
|
- name: Registry login
|
||||||
run: |
|
run: |
|
||||||
@@ -62,7 +58,7 @@ jobs:
|
|||||||
REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }}
|
REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }}
|
||||||
REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }}
|
REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }}
|
||||||
|
|
||||||
- name: Build Docker image
|
- name: Build and push image
|
||||||
run: |
|
run: |
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
|
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
|
||||||
|
|||||||
@@ -1,78 +0,0 @@
|
|||||||
# Forgejo Registry Secrets Configuration
|
|
||||||
|
|
||||||
## One-Time Setup (Org Level)
|
|
||||||
|
|
||||||
All repos in the `rock` org share the same Forgejo registry credentials.
|
|
||||||
|
|
||||||
### Configure at Organization Level
|
|
||||||
|
|
||||||
1. Navigate to: https://forgejo.riotpiao.com/rock
|
|
||||||
2. Click Settings (gear icon)
|
|
||||||
3. Go to: Actions → Secrets
|
|
||||||
4. Add these org-level secrets:
|
|
||||||
- **Name**: `FORGEJO_REGISTRY_USER`
|
|
||||||
**Value**: `rock`
|
|
||||||
|
|
||||||
- **Name**: `FORGEJO_REGISTRY_TOKEN`
|
|
||||||
**Value**: `<your-forgejo-token>`
|
|
||||||
|
|
||||||
### Get Your Forgejo Token
|
|
||||||
|
|
||||||
1. Go to: https://forgejo.riotpiao.com/user/settings/applications
|
|
||||||
2. Click "Generate New Token"
|
|
||||||
3. Set scopes: `api`, `read:registry`, `write:registry`
|
|
||||||
4. Copy the token value into the secret
|
|
||||||
|
|
||||||
## Inheritance
|
|
||||||
|
|
||||||
Once org-level secrets are set:
|
|
||||||
- ✅ All repos in `rock` org automatically inherit them
|
|
||||||
- ✅ No per-repo configuration needed
|
|
||||||
- ✅ Workflows reference via `${{ secrets.FORGEJO_REGISTRY_USER }}`
|
|
||||||
|
|
||||||
## Validation
|
|
||||||
|
|
||||||
Each repo's CI workflow includes a validation step:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
- name: Validate registry credentials
|
|
||||||
run: |
|
|
||||||
if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then
|
|
||||||
echo "❌ ERROR: Registry secrets not configured"
|
|
||||||
echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in org settings"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "✓ Registry credentials configured"
|
|
||||||
```
|
|
||||||
|
|
||||||
If secrets are missing, the validation step will fail with a clear error message pointing to this setup process.
|
|
||||||
|
|
||||||
## Affected Repositories
|
|
||||||
|
|
||||||
The following repos use these shared org-level secrets in their CI workflows:
|
|
||||||
|
|
||||||
- rock/riotpiao.com
|
|
||||||
- rock/homelab-frontend
|
|
||||||
- rock/poimen-workflows
|
|
||||||
- rock/poimen-memory
|
|
||||||
- rock/kmsvc-manage
|
|
||||||
|
|
||||||
All use the unified CI pattern:
|
|
||||||
- `test` job: runs on all branches + PRs (no registry access)
|
|
||||||
- `build-push` job: runs on main push only (requires registry credentials)
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
### "Registry secrets not configured" error
|
|
||||||
|
|
||||||
If CI fails with this error:
|
|
||||||
1. Check org settings: https://forgejo.riotpiao.com/rock/settings/actions/secrets
|
|
||||||
2. Verify both secrets exist and are not empty
|
|
||||||
3. Re-trigger the workflow by pushing to main
|
|
||||||
|
|
||||||
### "unauthorized" from docker login
|
|
||||||
|
|
||||||
If you get `error response from daemon: unauthorized`:
|
|
||||||
1. Check the token value is correct (copy-paste carefully)
|
|
||||||
2. Verify token has `read:registry` and `write:registry` scopes
|
|
||||||
3. Generate a new token if the old one expired
|
|
||||||
Reference in New Issue
Block a user