fix(ci-images): static build matrix for Gitea
Gitea expands a job's matrix when the run is created, before plan has any
outputs, so fromJSON(needs.plan.outputs.matrix) collapsed to a single empty
"Build ${{ matrix.key }}" job and nothing was ever built. The matrix is now
the fixed list of image keys; plan emits every image's spec with a build flag
and each matrix job looks its own entry up, no-opping when it wasn't picked.
Also document that both registry tokens need write:package -- the vault token
was read-only, so the gitea_ci_build_local bootstrap failed its push.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
8701ada7e2
commit
be50798096
@@ -59,6 +59,11 @@ belonging to the same `gitbot` user: Gitea authorises a package push by the
|
||||
token's owner, not by the path, so pushing to `gitbot/` means logging in as
|
||||
`gitbot`.
|
||||
|
||||
Both tokens need the `write:package` scope, not just `read:package`: the
|
||||
workflow pushes with `REGISTRY_TOKEN`, and the `gitea_ci_build_local` bootstrap
|
||||
below pushes with the vault token. A read-only token logs in and pulls fine but
|
||||
fails the push with `authentication required` (Gitea logs `reqPackageAccess`).
|
||||
|
||||
### Rebuilding
|
||||
|
||||
Normally nothing to do — edit a `files/Containerfile.*` or a version pin, push
|
||||
|
||||
Reference in New Issue
Block a user