CI: Arch-registry publish uses scoped REGISTRY_TOKEN, gated + non-fatal
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GLUwWE2KmFPzhKaf67tWbx
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
0754e9e3e3
commit
7361a39618
@@ -136,19 +136,24 @@ jobs:
|
|||||||
# (docs.gitea.com/usage/packages/arch). The PKGBUILD only repacks the
|
# (docs.gitea.com/usage/packages/arch). The PKGBUILD only repacks the
|
||||||
# release tarballs, so CARCH can produce both architectures from this
|
# release tarballs, so CARCH can produce both architectures from this
|
||||||
# one host. Consumers: see the infrastructure README.
|
# one host. Consumers: see the infrastructure README.
|
||||||
|
# Best-effort mirror to the instance Arch registry. The ephemeral
|
||||||
|
# GITHUB_TOKEN is not accepted as a package-write credential, so this
|
||||||
|
# uses a dedicated REGISTRY_TOKEN secret (a write:package token for bl);
|
||||||
|
# if it is unset the step is skipped, and continue-on-error keeps a
|
||||||
|
# registry hiccup from failing the release or the AUR push.
|
||||||
- name: Publish to the Arch package registry
|
- name: Publish to the Arch package registry
|
||||||
|
continue-on-error: true
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
if [ -z "${{ secrets.REGISTRY_TOKEN }}" ]; then
|
||||||
|
echo "::warning::REGISTRY_TOKEN not set — skipping Arch registry publish"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
cd aur
|
cd aur
|
||||||
# Build both arches here (repackaging the released binaries) and
|
|
||||||
# push each to the instance Arch registry. Use --packagelist for
|
|
||||||
# the exact filename (honours the runner's PKGEXT/PKGDEST) rather
|
|
||||||
# than globbing, and !strip (in the PKGBUILD) so packaging the
|
|
||||||
# foreign-arch binary on this host does not try to strip it.
|
|
||||||
for carch in aarch64 x86_64; do
|
for carch in aarch64 x86_64; do
|
||||||
pkgfile=$(CARCH="$carch" makepkg --packagelist | tail -1)
|
pkgfile=$(CARCH="$carch" makepkg --packagelist | tail -1)
|
||||||
CARCH="$carch" makepkg -f --nodeps --noconfirm --skipinteg
|
CARCH="$carch" makepkg -f --nodeps --noconfirm --skipinteg
|
||||||
curl --fail-with-body --user "${{ gitea.actor }}:${{ secrets.GITHUB_TOKEN }}" \
|
curl --fail-with-body --user "bl:${{ secrets.REGISTRY_TOKEN }}" \
|
||||||
--upload-file "$pkgfile" \
|
--upload-file "$pkgfile" \
|
||||||
"${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/arch/uhhm"
|
"${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/arch/uhhm"
|
||||||
done
|
done
|
||||||
|
|||||||
Reference in New Issue
Block a user