ci: move container images to the org registry namespace
Build destination, both builder-image references and the three publish pins now point at novoyuuparosk-wiki/*. The publish pins name a tag that does not exist in the new namespace until this run's build job pushes it and the pin job rewrites them, so publishes are briefly broken mid-run.
This commit is contained in:
@@ -14,7 +14,7 @@ jobs:
|
|||||||
# Daemonless image builder: kaniko :debug plus the /bin/sleep symlink
|
# Daemonless image builder: kaniko :debug plus the /bin/sleep symlink
|
||||||
# act needs for job-container PID 1 (see ci/Dockerfile.kaniko-act).
|
# act needs for job-container PID 1 (see ci/Dockerfile.kaniko-act).
|
||||||
# No docker socket, no privileges.
|
# No docker socket, no privileges.
|
||||||
image: pi5-16.local:3005/mikkeli/kaniko-act:v1.23.2-r2
|
image: pi5-16.local:3005/novoyuuparosk-wiki/kaniko-act:v1.23.2-r2
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Fetch source, build, push
|
- name: Fetch source, build, push
|
||||||
@@ -30,7 +30,7 @@ jobs:
|
|||||||
set -eu
|
set -eu
|
||||||
HOST="${URL_TO_GITEA#http://}"
|
HOST="${URL_TO_GITEA#http://}"
|
||||||
SHORT_SHA=$(echo "${GITHUB_SHA}" | cut -c1-7)
|
SHORT_SHA=$(echo "${GITHUB_SHA}" | cut -c1-7)
|
||||||
IMAGE="${HOST}/mikkeli/novoyuuparosk-wiki-runner"
|
IMAGE="${HOST}/novoyuuparosk-wiki/novoyuuparosk-wiki-runner"
|
||||||
|
|
||||||
# Source via Gitea archive API (no git/node in this image; repo is
|
# Source via Gitea archive API (no git/node in this image; repo is
|
||||||
# private — authenticate with the job's own per-run token)
|
# private — authenticate with the job's own per-run token)
|
||||||
@@ -64,7 +64,7 @@ jobs:
|
|||||||
# Freshly built runner image: git + GNU sed baked in, and it has no
|
# Freshly built runner image: git + GNU sed baked in, and it has no
|
||||||
# non-shell ENTRYPOINT, so it works as a job container as-is (unlike the
|
# non-shell ENTRYPOINT, so it works as a job container as-is (unlike the
|
||||||
# kaniko image above). Pulls :latest that the build job just pushed.
|
# kaniko image above). Pulls :latest that the build job just pushed.
|
||||||
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:latest
|
image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:latest
|
||||||
steps:
|
steps:
|
||||||
- name: Repoint publish workflows at the new image tag
|
- name: Repoint publish workflows at the new image tag
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -19,9 +19,10 @@ jobs:
|
|||||||
build:
|
build:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
# BOOTSTRAP: still the pre-migration image under `mikkeli`, because the
|
# Self-hosting: the current kaniko-act builds its own successor. The very
|
||||||
# org copy is what this run creates. Flip to the org path once it exists.
|
# first org build ran from `mikkeli/kaniko-act:v1.23.2-r2` instead, since
|
||||||
image: pi5-16.local:3005/mikkeli/kaniko-act:v1.23.2-r2
|
# this path did not exist yet.
|
||||||
|
image: pi5-16.local:3005/novoyuuparosk-wiki/kaniko-act:v1.23.2-r2
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Fetch source, build, push
|
- name: Fetch source, build, push
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ jobs:
|
|||||||
publish:
|
publish:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68
|
image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout ses-light-novel
|
- name: Checkout ses-light-novel
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ jobs:
|
|||||||
publish:
|
publish:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68
|
image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout ncmr-songs
|
- name: Checkout ncmr-songs
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ jobs:
|
|||||||
publish:
|
publish:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68
|
image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout tech-blogs
|
- name: Checkout tech-blogs
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ Container network mode: `host` — required so job containers can reach `localho
|
|||||||
|
|
||||||
### Job container image
|
### Job container image
|
||||||
|
|
||||||
All pipelines share a single pre-built Docker image, served from the Gitea registry at `pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner`. The `Dockerfile` is at the repo root. It bakes in system deps (git, pandoc, ca-certificates) and all pipeline Python packages so job containers start instantly with no install steps.
|
All pipelines share a single pre-built Docker image, served from the Gitea registry at `pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner`. The `Dockerfile` is at the repo root. It bakes in system deps (git, pandoc, ca-certificates) and all pipeline Python packages so job containers start instantly with no install steps.
|
||||||
|
|
||||||
The image builds automatically via [`.gitea/workflows/build-image.yml`](.gitea/workflows/build-image.yml), which triggers on pushes that touch the `Dockerfile`, any pipeline `requirements.txt`, or that workflow itself. It uses kaniko (daemonless, unprivileged) to build and push two tags: an immutable `:<short-sha>` and a moving `:latest`.
|
The image builds automatically via [`.gitea/workflows/build-image.yml`](.gitea/workflows/build-image.yml), which triggers on pushes that touch the `Dockerfile`, any pipeline `requirements.txt`, or that workflow itself. It uses kaniko (daemonless, unprivileged) to build and push two tags: an immutable `:<short-sha>` and a moving `:latest`.
|
||||||
|
|
||||||
@@ -91,7 +91,8 @@ Secrets and variables are scoped to the `novoyuuparosk-wiki` org, inherited by a
|
|||||||
| Ownership | This repo and all three source repos moved to the `novoyuuparosk-wiki` org. Secrets/variables re-created at org scope; runner re-registered instance-level so it serves org-owned runs | 2026-08-11 |
|
| Ownership | This repo and all three source repos moved to the `novoyuuparosk-wiki` org. Secrets/variables re-created at org scope; runner re-registered instance-level so it serves org-owned runs | 2026-08-11 |
|
||||||
| **This repo must stay public** | `act_runner` resolves a cross-repo `uses:` by cloning the callee **anonymously** — the job token is not applied. A private callee therefore 404s with `repository not found`, regardless of the caller sharing its owner. Shared ownership does **not** satisfy the read requirement. Alternative if it must be private again: Settings → Actions → General → collaborative owners (Gitea 1.26+), untested here | 2026-08-11 |
|
| **This repo must stay public** | `act_runner` resolves a cross-repo `uses:` by cloning the callee **anonymously** — the job token is not applied. A private callee therefore 404s with `repository not found`, regardless of the caller sharing its owner. Shared ownership does **not** satisfy the read requirement. Alternative if it must be private again: Settings → Actions → General → collaborative owners (Gitea 1.26+), untested here | 2026-08-11 |
|
||||||
| Runner cache masks this | The resolved callee is cached at `/root/.cache/act/<owner>-<repo>@<ref>`. Changing owner changes the key, so a working pipeline can break on a clone that had been served from cache for months. Suspect the cache before suspecting permissions | 2026-08-11 |
|
| Runner cache masks this | The resolved callee is cached at `/root/.cache/act/<owner>-<repo>@<ref>`. Changing owner changes the key, so a working pipeline can break on a clone that had been served from cache for months. Suspect the cache before suspecting permissions | 2026-08-11 |
|
||||||
| Container registry | Packages are not transferable in Gitea, so images stay at `pi5-16.local:3005/mikkeli/*` for now. Registry auth still uses the `mikkeli`-owned `PKGRW_PAT` | 2026-08-11 |
|
| Container registry | Gitea cannot transfer packages, so images were *rebuilt* into `pi5-16.local:3005/novoyuuparosk-wiki/*` rather than moved. `kaniko-act` bootstrapped via the new dispatch-only `build-kaniko-act.yml`, running in the old `mikkeli` copy; `novoyuuparosk-wiki-runner` came from a normal `build-image.yml` run. Registry auth is still the `mikkeli`-owned `PKGRW_PAT`, hence the `mikkeli:` username in the auth blob | 2026-08-11 |
|
||||||
|
| Old images left in place | The `mikkeli/*` package versions are orphaned but retained — nothing references them, and deleting a container version is irreversible. Safe to purge once the org images have proven themselves | 2026-08-11 |
|
||||||
| MediaWiki API path | `api.php` (classic action API) | 2026-06-09 |
|
| MediaWiki API path | `api.php` (classic action API) | 2026-06-09 |
|
||||||
| Branch naming (this repo) | `automation/<pipeline>` for pipeline-development branches | 2026-06-09 |
|
| Branch naming (this repo) | `automation/<pipeline>` for pipeline-development branches | 2026-06-09 |
|
||||||
| Variable naming | `URL_TO_GITEA` not `GITEA_URL` — Gitea blocks `GITEA_`/`GITHUB_` prefixes | 2026-06-09 |
|
| Variable naming | `URL_TO_GITEA` not `GITEA_URL` — Gitea blocks `GITEA_`/`GITHUB_` prefixes | 2026-06-09 |
|
||||||
|
|||||||
@@ -5,10 +5,11 @@
|
|||||||
# (busybox lives under /busybox; /bin/sh is already symlinked) nor /tmp.
|
# (busybox lives under /busybox; /bin/sh is already symlinked) nor /tmp.
|
||||||
# This wrapper adds exactly those two. Nothing else changes.
|
# This wrapper adds exactly those two. Nothing else changes.
|
||||||
#
|
#
|
||||||
# Bootstrap: the first build of this image is done manually on the host
|
# Bootstrap: the very first build of this image was done manually on the host
|
||||||
# (docker build -f ci/Dockerfile.kaniko-act -t <registry>/mikkeli/kaniko-act:<ver> .)
|
# (docker build -f ci/Dockerfile.kaniko-act -t <registry>/<owner>/kaniko-act:<ver> .)
|
||||||
# because no builder image exists yet. Later version bumps can be built by
|
# because no builder image existed yet. Version bumps are now built by
|
||||||
# the build-image workflow itself, using the previous kaniko-act.
|
# .gitea/workflows/build-kaniko-act.yml (dispatch-only), which runs in the
|
||||||
|
# previous kaniko-act — confirmed working when the image moved to the org.
|
||||||
FROM gcr.io/kaniko-project/executor:v1.23.2-debug
|
FROM gcr.io/kaniko-project/executor:v1.23.2-debug
|
||||||
SHELL ["/busybox/sh", "-c"]
|
SHELL ["/busybox/sh", "-c"]
|
||||||
RUN ln -sf /busybox/sleep /bin/sleep && mkdir -p -m 1777 /tmp
|
RUN ln -sf /busybox/sleep /bin/sleep && mkdir -p -m 1777 /tmp
|
||||||
|
|||||||
Reference in New Issue
Block a user