build-image.yml now pushes a moving :latest tag alongside :<short-sha>,
and a follow-up pin job (running in :latest) rewrites the image pin in all
three publish-*.yml to the new sha and commits it back to master with
FAPAT. Publish workflows keep immutable sha pins, kept current with no
manual bump. No rebuild loop: the pin commit only touches workflow_call
files. Root README image-flow section updated to match.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fetch uses the job's per-run auto-token (repo-scoped, nothing stored);
push moves to the PKGRW_PAT user secret, separating CI credentials
from the host's docker login token.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
kaniko's scratch image has no /tmp; the build script and act's
RUNNER_TEMP both assume it exists.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
act starts job containers with entrypoint /bin/sleep, which kaniko's
scratch-based image lacks (busybox lives under /busybox). kaniko-act
adds the single missing symlink; bootstrap build is manual, documented
in the Dockerfile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Daemonless image build inside the job container itself
(kaniko :debug). Source fetched via Gitea archive API, pushed to the
Gitea registry tagged with the short commit SHA. Triggered by changes
to Dockerfile, any pipeline requirements.txt, or this workflow.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>