bf8fef9190
The Gitea instance's act_runner is the CI that actually executes here; GitHub Actions on the mirror isn't confirmed to run at all (and a push-mirror lacking the "workflow" PAT scope can silently drop .github/workflows changes anyway). Add a GHCR login/push to the existing .gitea/workflows/docker-publish.yml job instead, so one build produces tags on both the Gitea registry and ghcr.io. Drop the now-redundant .github/workflows/docker-publish.yml. Requires a new repo secret GHCR_TOKEN: a GitHub PAT with write:packages scope (separate from REGISTRY_TOKEN, which is scoped to the Gitea registry).
47 lines
1.2 KiB
YAML
47 lines
1.2 KiB
YAML
name: Publish Docker image
|
|
|
|
on:
|
|
push:
|
|
branches: [main, master]
|
|
tags: ['v*']
|
|
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
|
|
jobs:
|
|
build-and-push:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Compute lowercase image name
|
|
run: echo "IMAGE_NAME=$(echo '${{ github.repository }}' | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
|
|
|
|
- name: Log in to Gitea container registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ${{ vars.REGISTRY_HOST }}
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.REGISTRY_TOKEN }}
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GHCR_TOKEN }}
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v6
|
|
with:
|
|
context: .
|
|
push: true
|
|
tags: |
|
|
${{ vars.REGISTRY_HOST }}/${{ env.IMAGE_NAME }}:latest
|
|
${{ vars.REGISTRY_HOST }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
|
|
ghcr.io/${{ env.IMAGE_NAME }}:latest
|
|
ghcr.io/${{ env.IMAGE_NAME }}:${{ github.sha }}
|