From 7842a757cdbb33931376d6b7bca2dab072c8508a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Mon, 31 Aug 2026 13:41:14 -0300 Subject: [PATCH] fix: use explicit Gitea registry credentials --- .github/workflows/ci.yml | 2 +- PORTAINER.md | 9 +++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c37730f..d83572b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -30,7 +30,7 @@ jobs: steps: - uses: actions/checkout@v4 - name: Sign in to the Gitea Container Registry - run: echo "${{ secrets.GITEA_TOKEN }}" | docker login gitea.blyzer.com.br -u "${{ gitea.actor }}" --password-stdin + run: echo "${{ secrets.REGISTRY_TOKEN }}" | docker login gitea.blyzer.com.br -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin - name: Build and publish API run: | docker build --pull -f Dockerfile.api -t gitea.blyzer.com.br/blyzer/compor-academy-api:latest . diff --git a/PORTAINER.md b/PORTAINER.md index 8152fa9..a672391 100644 --- a/PORTAINER.md +++ b/PORTAINER.md @@ -4,6 +4,15 @@ Use `docker-compose.yml` as a Portainer Stack from this repository. It deploys t This is a Docker Swarm stack: Portainer pulls prebuilt API and web images from the Gitea Container Registry. It never builds Dockerfiles itself. +## Gitea Actions registry secrets + +Create these repository-level Action secrets in Gitea before pushing to `main`: + +- `REGISTRY_USERNAME`: the Gitea username that owns a package-write token. +- `REGISTRY_TOKEN`: a Gitea personal access token for that user with package read/write permission. + +The built-in Actions job token can be disabled or lack registry scope on self-hosted Gitea instances, so the image publishing job intentionally uses these explicit secrets. + ## Required Portainer environment variables - `POSTGRES_PASSWORD`: a long, unique database password. Avoid characters that are not URL-safe because it is used in `DATABASE_URL`.