ci: best-effort registry login so smoke pulls from the mirror (#137) #139

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/137-ci-registry-login in i main 2026-07-19 09:51:11 +00:00
Ägare

Part of #137 (the CI-side of step 2). The prior PR (#138) made smoke-containers.py prefer the in-instance mirror with upstream fallback + retry; this lets CI actually authenticate to that mirror.

Why: the Forgejo registry is not anonymously pullable (git.gitborg.se/v2/ → 401), and making the gitborg org public to fix that is unacceptable (exposes private repos). So CI must log in.

Change: a best-effort podman login git.gitborg.se step before the container smoke, using a read-only gitborg-ci PAT in the REGISTRY_READ_TOKEN Actions secret.

  • Non-fatal by design: if the secret is unset or login fails, smoke-containers.py falls back to pulling upstream (with retry), so CI never breaks. Token is passed via env (not inlined into the script) and printf | --password-stdin.

Operator prerequisite (out-of-band, for the mirror to actually be used):

  1. Apply site.yml so the registry-mirror timer populates bitborg/{forgejo,postgres,caddy,kanidm} (step 1 of #137).
  2. Mint a read:package PAT on gitborg-ci and set it: fj actions secrets set REGISTRY_READ_TOKEN (or the web UI). Least-privilege — read only, distinct from the write token the mirror push uses.

Until both are done, smoke keeps pulling upstream (already resilient via the retry from #138). Validated: ci.yml is valid YAML and prettier-clean.

Part of #137 (the CI-side of step 2). The prior PR (#138) made `smoke-containers.py` prefer the in-instance mirror with upstream fallback + retry; this lets CI actually authenticate to that mirror. **Why:** the Forgejo registry is not anonymously pullable (`git.gitborg.se/v2/` → 401), and making the `gitborg` org public to fix that is unacceptable (exposes private repos). So CI must log in. **Change:** a best-effort `podman login git.gitborg.se` step before the container smoke, using a read-only `gitborg-ci` PAT in the `REGISTRY_READ_TOKEN` Actions secret. - **Non-fatal by design:** if the secret is unset or login fails, `smoke-containers.py` falls back to pulling upstream (with retry), so CI never breaks. Token is passed via `env` (not inlined into the script) and `printf | --password-stdin`. **Operator prerequisite (out-of-band, for the mirror to actually be used):** 1. Apply `site.yml` so the registry-mirror timer populates `bitborg/{forgejo,postgres,caddy,kanidm}` (step 1 of #137). 2. Mint a **read:package** PAT on `gitborg-ci` and set it: `fj actions secrets set REGISTRY_READ_TOKEN` (or the web UI). Least-privilege — read only, distinct from the write token the mirror push uses. Until both are done, smoke keeps pulling upstream (already resilient via the retry from #138). Validated: `ci.yml` is valid YAML and prettier-clean.
supernaut lade till 1 incheckning 2026-07-19 09:37:37 +00:00
ci: best-effort registry login so smoke pulls from the mirror (#137)
En del kontroller misslyckades
ci / ci (pull_request) Failing after 3m13s
4bbf321948
Anonymous pull from the Forgejo registry is off (git.gitborg.se/v2/ → 401), so the
smoke test can only reach the in-instance mirror after authenticating. Add a
best-effort 'podman login git.gitborg.se' before the container smoke, using a
read-only gitborg-ci PAT in the REGISTRY_READ_TOKEN Actions secret. Non-fatal: if
the secret is unset or login fails, smoke-containers.py falls back to pulling
upstream (with retry), so CI never breaks. Token passed via env, not inlined.

Completes the CI side of #137; the operator still (1) applies site.yml to populate
the mirror and (2) sets the REGISTRY_READ_TOKEN secret.
supernaut lade till 1 incheckning 2026-07-19 09:46:29 +00:00
fix(ci): smoke SKIPs (not FAILs) on a transient upstream registry outage (#137)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m49s
0006cde075
Run #68 failed only because codeberg.org 503'd while pulling forgejo:16.0.0 (its
sole source; the mirror isn't populated/CI-pullable yet). A registry being
unreachable is not what this smoke asserts (exec-under-caps, the #94 class) — the
image simply couldn't be obtained, so the result is INCONCLUSIVE, not a regression.
Classify the exhausted-fallback error: transient (5xx/429/timeout/DNS/connection/
TLS) → SKIP (surfaced, non-fatal); a definite error (manifest-unknown/404/auth/bad
ref) still FAILs. Ends the external-registry-outage false-failure class; verified
the classifier against the real 503/504 strings + negative cases.
supernaut sammanfogade incheckning cbd3dfd1e7 till main 2026-07-19 09:51:11 +00:00
supernaut tog bort grenen feat/137-ci-registry-login 2026-07-19 09:51:11 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!139
Ingen beskrivning angiven.