ci: move container images to the org registry namespace
/ build (push) Failing after 2s
/ pin (push) Has been skipped

Build destination, both builder-image references and the three publish
pins now point at novoyuuparosk-wiki/*. The publish pins name a tag that
does not exist in the new namespace until this run's build job pushes it
and the pin job rewrites them, so publishes are briefly broken mid-run.
This commit is contained in:
2026-08-11 20:32:45 +09:00
parent 4919ce9450
commit 905a1051a8
7 changed files with 18 additions and 15 deletions
+3 -3
View File
@@ -14,7 +14,7 @@ jobs:
# Daemonless image builder: kaniko :debug plus the /bin/sleep symlink # Daemonless image builder: kaniko :debug plus the /bin/sleep symlink
# act needs for job-container PID 1 (see ci/Dockerfile.kaniko-act). # act needs for job-container PID 1 (see ci/Dockerfile.kaniko-act).
# No docker socket, no privileges. # No docker socket, no privileges.
image: pi5-16.local:3005/mikkeli/kaniko-act:v1.23.2-r2 image: pi5-16.local:3005/novoyuuparosk-wiki/kaniko-act:v1.23.2-r2
steps: steps:
- name: Fetch source, build, push - name: Fetch source, build, push
@@ -30,7 +30,7 @@ jobs:
set -eu set -eu
HOST="${URL_TO_GITEA#http://}" HOST="${URL_TO_GITEA#http://}"
SHORT_SHA=$(echo "${GITHUB_SHA}" | cut -c1-7) SHORT_SHA=$(echo "${GITHUB_SHA}" | cut -c1-7)
IMAGE="${HOST}/mikkeli/novoyuuparosk-wiki-runner" IMAGE="${HOST}/novoyuuparosk-wiki/novoyuuparosk-wiki-runner"
# Source via Gitea archive API (no git/node in this image; repo is # Source via Gitea archive API (no git/node in this image; repo is
# private — authenticate with the job's own per-run token) # private — authenticate with the job's own per-run token)
@@ -64,7 +64,7 @@ jobs:
# Freshly built runner image: git + GNU sed baked in, and it has no # Freshly built runner image: git + GNU sed baked in, and it has no
# non-shell ENTRYPOINT, so it works as a job container as-is (unlike the # non-shell ENTRYPOINT, so it works as a job container as-is (unlike the
# kaniko image above). Pulls :latest that the build job just pushed. # kaniko image above). Pulls :latest that the build job just pushed.
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:latest image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:latest
steps: steps:
- name: Repoint publish workflows at the new image tag - name: Repoint publish workflows at the new image tag
env: env:
+4 -3
View File
@@ -19,9 +19,10 @@ jobs:
build: build:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
# BOOTSTRAP: still the pre-migration image under `mikkeli`, because the # Self-hosting: the current kaniko-act builds its own successor. The very
# org copy is what this run creates. Flip to the org path once it exists. # first org build ran from `mikkeli/kaniko-act:v1.23.2-r2` instead, since
image: pi5-16.local:3005/mikkeli/kaniko-act:v1.23.2-r2 # this path did not exist yet.
image: pi5-16.local:3005/novoyuuparosk-wiki/kaniko-act:v1.23.2-r2
steps: steps:
- name: Fetch source, build, push - name: Fetch source, build, push
+1 -1
View File
@@ -10,7 +10,7 @@ jobs:
publish: publish:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68 image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
steps: steps:
- name: Checkout ses-light-novel - name: Checkout ses-light-novel
+1 -1
View File
@@ -19,7 +19,7 @@ jobs:
publish: publish:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68 image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
steps: steps:
- name: Checkout ncmr-songs - name: Checkout ncmr-songs
+1 -1
View File
@@ -10,7 +10,7 @@ jobs:
publish: publish:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
image: pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner:6dc9f68 image: pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner:6dc9f68
steps: steps:
- name: Checkout tech-blogs - name: Checkout tech-blogs
+3 -2
View File
@@ -53,7 +53,7 @@ Container network mode: `host` — required so job containers can reach `localho
### Job container image ### Job container image
All pipelines share a single pre-built Docker image, served from the Gitea registry at `pi5-16.local:3005/mikkeli/novoyuuparosk-wiki-runner`. The `Dockerfile` is at the repo root. It bakes in system deps (git, pandoc, ca-certificates) and all pipeline Python packages so job containers start instantly with no install steps. All pipelines share a single pre-built Docker image, served from the Gitea registry at `pi5-16.local:3005/novoyuuparosk-wiki/novoyuuparosk-wiki-runner`. The `Dockerfile` is at the repo root. It bakes in system deps (git, pandoc, ca-certificates) and all pipeline Python packages so job containers start instantly with no install steps.
The image builds automatically via [`.gitea/workflows/build-image.yml`](.gitea/workflows/build-image.yml), which triggers on pushes that touch the `Dockerfile`, any pipeline `requirements.txt`, or that workflow itself. It uses kaniko (daemonless, unprivileged) to build and push two tags: an immutable `:<short-sha>` and a moving `:latest`. The image builds automatically via [`.gitea/workflows/build-image.yml`](.gitea/workflows/build-image.yml), which triggers on pushes that touch the `Dockerfile`, any pipeline `requirements.txt`, or that workflow itself. It uses kaniko (daemonless, unprivileged) to build and push two tags: an immutable `:<short-sha>` and a moving `:latest`.
@@ -91,7 +91,8 @@ Secrets and variables are scoped to the `novoyuuparosk-wiki` org, inherited by a
| Ownership | This repo and all three source repos moved to the `novoyuuparosk-wiki` org. Secrets/variables re-created at org scope; runner re-registered instance-level so it serves org-owned runs | 2026-08-11 | | Ownership | This repo and all three source repos moved to the `novoyuuparosk-wiki` org. Secrets/variables re-created at org scope; runner re-registered instance-level so it serves org-owned runs | 2026-08-11 |
| **This repo must stay public** | `act_runner` resolves a cross-repo `uses:` by cloning the callee **anonymously** — the job token is not applied. A private callee therefore 404s with `repository not found`, regardless of the caller sharing its owner. Shared ownership does **not** satisfy the read requirement. Alternative if it must be private again: Settings → Actions → General → collaborative owners (Gitea 1.26+), untested here | 2026-08-11 | | **This repo must stay public** | `act_runner` resolves a cross-repo `uses:` by cloning the callee **anonymously** — the job token is not applied. A private callee therefore 404s with `repository not found`, regardless of the caller sharing its owner. Shared ownership does **not** satisfy the read requirement. Alternative if it must be private again: Settings → Actions → General → collaborative owners (Gitea 1.26+), untested here | 2026-08-11 |
| Runner cache masks this | The resolved callee is cached at `/root/.cache/act/<owner>-<repo>@<ref>`. Changing owner changes the key, so a working pipeline can break on a clone that had been served from cache for months. Suspect the cache before suspecting permissions | 2026-08-11 | | Runner cache masks this | The resolved callee is cached at `/root/.cache/act/<owner>-<repo>@<ref>`. Changing owner changes the key, so a working pipeline can break on a clone that had been served from cache for months. Suspect the cache before suspecting permissions | 2026-08-11 |
| Container registry | Packages are not transferable in Gitea, so images stay at `pi5-16.local:3005/mikkeli/*` for now. Registry auth still uses the `mikkeli`-owned `PKGRW_PAT` | 2026-08-11 | | Container registry | Gitea cannot transfer packages, so images were *rebuilt* into `pi5-16.local:3005/novoyuuparosk-wiki/*` rather than moved. `kaniko-act` bootstrapped via the new dispatch-only `build-kaniko-act.yml`, running in the old `mikkeli` copy; `novoyuuparosk-wiki-runner` came from a normal `build-image.yml` run. Registry auth is still the `mikkeli`-owned `PKGRW_PAT`, hence the `mikkeli:` username in the auth blob | 2026-08-11 |
| Old images left in place | The `mikkeli/*` package versions are orphaned but retained — nothing references them, and deleting a container version is irreversible. Safe to purge once the org images have proven themselves | 2026-08-11 |
| MediaWiki API path | `api.php` (classic action API) | 2026-06-09 | | MediaWiki API path | `api.php` (classic action API) | 2026-06-09 |
| Branch naming (this repo) | `automation/<pipeline>` for pipeline-development branches | 2026-06-09 | | Branch naming (this repo) | `automation/<pipeline>` for pipeline-development branches | 2026-06-09 |
| Variable naming | `URL_TO_GITEA` not `GITEA_URL` — Gitea blocks `GITEA_`/`GITHUB_` prefixes | 2026-06-09 | | Variable naming | `URL_TO_GITEA` not `GITEA_URL` — Gitea blocks `GITEA_`/`GITHUB_` prefixes | 2026-06-09 |
+5 -4
View File
@@ -5,10 +5,11 @@
# (busybox lives under /busybox; /bin/sh is already symlinked) nor /tmp. # (busybox lives under /busybox; /bin/sh is already symlinked) nor /tmp.
# This wrapper adds exactly those two. Nothing else changes. # This wrapper adds exactly those two. Nothing else changes.
# #
# Bootstrap: the first build of this image is done manually on the host # Bootstrap: the very first build of this image was done manually on the host
# (docker build -f ci/Dockerfile.kaniko-act -t <registry>/mikkeli/kaniko-act:<ver> .) # (docker build -f ci/Dockerfile.kaniko-act -t <registry>/<owner>/kaniko-act:<ver> .)
# because no builder image exists yet. Later version bumps can be built by # because no builder image existed yet. Version bumps are now built by
# the build-image workflow itself, using the previous kaniko-act. # .gitea/workflows/build-kaniko-act.yml (dispatch-only), which runs in the
# previous kaniko-act — confirmed working when the image moved to the org.
FROM gcr.io/kaniko-project/executor:v1.23.2-debug FROM gcr.io/kaniko-project/executor:v1.23.2-debug
SHELL ["/busybox/sh", "-c"] SHELL ["/busybox/sh", "-c"]
RUN ln -sf /busybox/sleep /bin/sleep && mkdir -p -m 1777 /tmp RUN ln -sf /busybox/sleep /bin/sleep && mkdir -p -m 1777 /tmp