Files
riotpiao.com/REGISTRY_SETUP.md
T
Story Crater Bot 1f66db0ba4 fix: validate registry credentials before docker login
Add credential validation step to catch missing secrets early with clear error message.
Use direct secret injection (not env vars) for better security.
Isolate docker config to /tmp/docker-config.
2026-09-06 23:34:54 -07:00

2.3 KiB

Forgejo Registry Secrets Configuration

One-Time Setup (Org Level)

All repos in the rock org share the same Forgejo registry credentials.

Configure at Organization Level

  1. Navigate to: https://forgejo.riotpiao.com/rock
  2. Click Settings (gear icon)
  3. Go to: Actions → Secrets
  4. Add these org-level secrets:
    • Name: FORGEJO_REGISTRY_USER Value: rock

    • Name: FORGEJO_REGISTRY_TOKEN Value: <your-forgejo-token>

Get Your Forgejo Token

  1. Go to: https://forgejo.riotpiao.com/user/settings/applications
  2. Click "Generate New Token"
  3. Set scopes: api, read:registry, write:registry
  4. Copy the token value into the secret

Inheritance

Once org-level secrets are set:

  • All repos in rock org automatically inherit them
  • No per-repo configuration needed
  • Workflows reference via ${{ secrets.FORGEJO_REGISTRY_USER }}

Validation

Each repo's CI workflow includes a validation step:

- name: Validate registry credentials
  run: |
    if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then
      echo "❌ ERROR: Registry secrets not configured"
      echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in org settings"
      exit 1
    fi
    echo "✓ Registry credentials configured"

If secrets are missing, the validation step will fail with a clear error message pointing to this setup process.

Affected Repositories

The following repos use these shared org-level secrets in their CI workflows:

  • rock/riotpiao.com
  • rock/homelab-frontend
  • rock/poimen-workflows
  • rock/poimen-memory
  • rock/kmsvc-manage

All use the unified CI pattern:

  • test job: runs on all branches + PRs (no registry access)
  • build-push job: runs on main push only (requires registry credentials)

Troubleshooting

"Registry secrets not configured" error

If CI fails with this error:

  1. Check org settings: https://forgejo.riotpiao.com/rock/settings/actions/secrets
  2. Verify both secrets exist and are not empty
  3. Re-trigger the workflow by pushing to main

"unauthorized" from docker login

If you get error response from daemon: unauthorized:

  1. Check the token value is correct (copy-paste carefully)
  2. Verify token has read:registry and write:registry scopes
  3. Generate a new token if the old one expired