Files
bookhoard/.gitea/workflows/release.yml
T
john-okeefe 3c9e4d8126 fix(ci): use REGISTRY_TOKEN PAT secret for registry login
Gitea's auto GITHUB_TOKEN lacks the package scope needed to push to the container registry, causing the login step to fail. Switch the login password to a PAT stored as the REGISTRY_TOKEN repo Actions secret (scopes: write:package, read:package).
2026-07-29 17:07:00 -04:00

45 lines
1.4 KiB
YAML

name: Release
# Builds and publishes the Bookhoard container image to the Gitea container registry.
# Triggered ONLY by a version tag push (pushing to main does nothing), so work-in-progress
# commits never ship. Each release publishes two image tags: the version and "latest".
on:
push:
tags:
- 'v*'
workflow_dispatch:
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to Gitea Container Registry
uses: docker/login-action@v3
with:
registry: git.linuxhg.com
username: ${{ gitea.actor }}
# PAT stored as a repo Actions secret (auto GITHUB_TOKEN lacks package scope in Gitea)
password: ${{ secrets.REGISTRY_TOKEN }}
- name: Build and push image
uses: docker/build-push-action@v5
with:
context: .
file: ./Dockerfile
push: true
# Publishes both the exact version (e.g. v0.2.0) and the movable "latest" tag.
# Deployments default to "latest" via ${IMAGE_TAG:-latest} in docker-compose.yml;
# pin or roll back by setting IMAGE_TAG in .env.
tags: |
git.linuxhg.com/bookhoard/bookhoard:${{ gitea.ref_name }}
git.linuxhg.com/bookhoard/bookhoard:latest