diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 7435d40..a788635 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -136,19 +136,24 @@ jobs: # (docs.gitea.com/usage/packages/arch). The PKGBUILD only repacks the # release tarballs, so CARCH can produce both architectures from this # one host. Consumers: see the infrastructure README. + # Best-effort mirror to the instance Arch registry. The ephemeral + # GITHUB_TOKEN is not accepted as a package-write credential, so this + # uses a dedicated REGISTRY_TOKEN secret (a write:package token for bl); + # if it is unset the step is skipped, and continue-on-error keeps a + # registry hiccup from failing the release or the AUR push. - name: Publish to the Arch package registry + continue-on-error: true run: | set -euo pipefail + if [ -z "${{ secrets.REGISTRY_TOKEN }}" ]; then + echo "::warning::REGISTRY_TOKEN not set — skipping Arch registry publish" + exit 0 + fi cd aur - # Build both arches here (repackaging the released binaries) and - # push each to the instance Arch registry. Use --packagelist for - # the exact filename (honours the runner's PKGEXT/PKGDEST) rather - # than globbing, and !strip (in the PKGBUILD) so packaging the - # foreign-arch binary on this host does not try to strip it. for carch in aarch64 x86_64; do pkgfile=$(CARCH="$carch" makepkg --packagelist | tail -1) CARCH="$carch" makepkg -f --nodeps --noconfirm --skipinteg - curl --fail-with-body --user "${{ gitea.actor }}:${{ secrets.GITHUB_TOKEN }}" \ + curl --fail-with-body --user "bl:${{ secrets.REGISTRY_TOKEN }}" \ --upload-file "$pkgfile" \ "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/arch/uhhm" done