Fetch uses the job's per-run auto-token (repo-scoped, nothing stored); push moves to the PKGRW_PAT user secret, separating CI credentials from the host's docker login token. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -21,7 +21,10 @@ jobs:
|
|||||||
# kaniko image has no bash — busybox sh only
|
# kaniko image has no bash — busybox sh only
|
||||||
shell: sh
|
shell: sh
|
||||||
env:
|
env:
|
||||||
PKG_TOKEN: ${{ secrets.PKG_TOKEN }}
|
# package r/w PAT (user-level secret) — registry push only
|
||||||
|
PKG_TOKEN: ${{ secrets.PKGRW_PAT }}
|
||||||
|
# per-run auto-token, read access to this repo only — source fetch
|
||||||
|
JOB_TOKEN: ${{ github.token }}
|
||||||
URL_TO_GITEA: ${{ vars.URL_TO_GITEA }}
|
URL_TO_GITEA: ${{ vars.URL_TO_GITEA }}
|
||||||
run: |
|
run: |
|
||||||
set -eu
|
set -eu
|
||||||
@@ -30,9 +33,9 @@ jobs:
|
|||||||
IMAGE="${HOST}/mikkeli/novoyuuparosk-wiki-runner"
|
IMAGE="${HOST}/mikkeli/novoyuuparosk-wiki-runner"
|
||||||
|
|
||||||
# Source via Gitea archive API (no git/node in this image; repo is
|
# Source via Gitea archive API (no git/node in this image; repo is
|
||||||
# public so the download is anonymous — PKG_TOKEN is push-only)
|
# private — authenticate with the job's own per-run token)
|
||||||
wget -qO /tmp/src.tar.gz \
|
wget -qO /tmp/src.tar.gz \
|
||||||
"http://${HOST}/api/v1/repos/mikkeli/novoyuuparosk-auto-wiki/archive/${GITHUB_SHA}.tar.gz"
|
"http://mikkeli:${JOB_TOKEN}@${HOST}/api/v1/repos/mikkeli/novoyuuparosk-auto-wiki/archive/${GITHUB_SHA}.tar.gz"
|
||||||
mkdir -p /tmp/src
|
mkdir -p /tmp/src
|
||||||
tar -xzf /tmp/src.tar.gz -C /tmp/src --strip-components=1
|
tar -xzf /tmp/src.tar.gz -C /tmp/src --strip-components=1
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user