Every push to master was triggering a build+push, since that's where
day-to-day commits land. Switch to two deliberate channels instead:
pushing to dev produces a rolling :dev tag for testing, and pushing a
v* tag produces :latest + the version tag for real releases. Plain
commits/merges to master/main no longer build anything on their own.
The Gitea instance's act_runner is the CI that actually executes here;
GitHub Actions on the mirror isn't confirmed to run at all (and a
push-mirror lacking the "workflow" PAT scope can silently drop
.github/workflows changes anyway). Add a GHCR login/push to the
existing .gitea/workflows/docker-publish.yml job instead, so one
build produces tags on both the Gitea registry and ghcr.io. Drop the
now-redundant .github/workflows/docker-publish.yml.
Requires a new repo secret GHCR_TOKEN: a GitHub PAT with write:packages
scope (separate from REGISTRY_TOKEN, which is scoped to the Gitea
registry).
github.repository preserves the owner's case (jeanGaston), but OCI
registries reject uppercase repository names. Compute a lowercased
IMAGE_NAME env var and use it for both tags instead.
The auto-injected GITHUB_TOKEN isn't authorized against this Gitea
instance's container registry (401 unauthorized), so use a repo
secret backed by a personal access token with package scope instead.
Gitea rejects variable/secret names starting with GITEA_ or GITHUB_
(reserved for system-injected values), which is why GITEA_REGISTRY
couldn't be created in repo settings.
act_runner's default registration only exposes ubuntu-latest (and
similar ubuntu-* labels); "docker" isn't a real label unless a runner
was explicitly configured with it.