ci: best-effort registry login so smoke pulls from the mirror (#137) #139
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!139
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/137-ci-registry-login"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Part of #137 (the CI-side of step 2). The prior PR (#138) made
smoke-containers.pyprefer the in-instance mirror with upstream fallback + retry; this lets CI actually authenticate to that mirror.Why: the Forgejo registry is not anonymously pullable (
git.gitborg.se/v2/→ 401), and making thegitborgorg public to fix that is unacceptable (exposes private repos). So CI must log in.Change: a best-effort
podman login git.gitborg.sestep before the container smoke, using a read-onlygitborg-ciPAT in theREGISTRY_READ_TOKENActions secret.smoke-containers.pyfalls back to pulling upstream (with retry), so CI never breaks. Token is passed viaenv(not inlined into the script) andprintf | --password-stdin.Operator prerequisite (out-of-band, for the mirror to actually be used):
site.ymlso the registry-mirror timer populatesbitborg/{forgejo,postgres,caddy,kanidm}(step 1 of #137).gitborg-ciand set it:fj actions secrets set REGISTRY_READ_TOKEN(or the web UI). Least-privilege — read only, distinct from the write token the mirror push uses.Until both are done, smoke keeps pulling upstream (already resilient via the retry from #138). Validated:
ci.ymlis valid YAML and prettier-clean.