Files
lovelope/.gitea/workflows/docker-publish.yml
T
jeanGaston bf8fef9190 ci: push to GHCR from the Gitea workflow instead of a separate one
The Gitea instance's act_runner is the CI that actually executes here;
GitHub Actions on the mirror isn't confirmed to run at all (and a
push-mirror lacking the "workflow" PAT scope can silently drop
.github/workflows changes anyway). Add a GHCR login/push to the
existing .gitea/workflows/docker-publish.yml job instead, so one
build produces tags on both the Gitea registry and ghcr.io. Drop the
now-redundant .github/workflows/docker-publish.yml.

Requires a new repo secret GHCR_TOKEN: a GitHub PAT with write:packages
scope (separate from REGISTRY_TOKEN, which is scoped to the Gitea
registry).
2026-07-30 11:50:38 +02:00

47 lines
1.2 KiB
YAML

name: Publish Docker image
on:
push:
branches: [main, master]
tags: ['v*']
permissions:
contents: read
packages: write
jobs:
build-and-push:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- name: Compute lowercase image name
run: echo "IMAGE_NAME=$(echo '${{ github.repository }}' | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
- name: Log in to Gitea container registry
uses: docker/login-action@v3
with:
registry: ${{ vars.REGISTRY_HOST }}
username: ${{ github.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GHCR_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v6
with:
context: .
push: true
tags: |
${{ vars.REGISTRY_HOST }}/${{ env.IMAGE_NAME }}:latest
${{ vars.REGISTRY_HOST }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
ghcr.io/${{ env.IMAGE_NAME }}:latest
ghcr.io/${{ env.IMAGE_NAME }}:${{ github.sha }}