Files
claude-sbx/.gitea/workflows/build.yml
T
mroberts b79bf35e70
build / build (push) Failing after 3m38s
Target the self-hosted runner label and harden the workflow
ubuntu-latest matches no runner on this forge, so both the main push and the
v1.0.0 tag queued nothing at all. The runner is labelled linux.

actions/checkout is pinned to a commit rather than a tag, and to v4.4.0 rather
than the current v7.0.1: v7 declares node24, which act_runner does not provide.
regctl moves out of /usr/local/bin, which a self-hosted runner cannot write to
without sudo, and is pinned to a release rather than tracking latest.

Clean under actionlint and zizmor --persona=auditor. Every expansion moves into
env so nothing interpolates into a shell body. secrets-outside-env is suppressed
deliberately: Gitea has no deployment environment protection rules, so a
dedicated environment would add ceremony without a security boundary.
2026-07-31 08:25:20 -05:00

58 lines
1.6 KiB
YAML

name: build
on:
push:
branches: [main]
tags: ['v*']
env:
REGISTRY: git.mroberts.dev
IMAGE: git.mroberts.dev/mroberts/claude-sbx
jobs:
build:
runs-on: linux
steps:
- uses: actions/checkout@v4
- name: Install regctl
run: |
mkdir -p "$HOME/.local/bin"
curl -fsSL -o "$HOME/.local/bin/regctl" \
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
chmod +x "$HOME/.local/bin/regctl"
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
- name: Resolve tag
id: tag
run: |
if [[ "$GITHUB_REF" == refs/tags/* ]]; then
printf 'value=%s\n' "${GITHUB_REF#refs/tags/}" >>"$GITHUB_OUTPUT"
else
printf 'value=edge\n' >>"$GITHUB_OUTPUT"
fi
- name: Build
run: docker build -t "$IMAGE:${{ steps.tag.outputs.value }}" .
- name: Export image
run: docker save "$IMAGE:${{ steps.tag.outputs.value }}" -o image.tar
- name: Push
run: |
regctl registry login "$REGISTRY" \
--user "${{ github.actor }}" \
--pass-stdin <<<"${{ secrets.GITEA_TOKEN }}"
regctl registry set "$REGISTRY" \
--blob-chunk 50000000 \
--blob-max 50000000
regctl image import "$IMAGE:${{ steps.tag.outputs.value }}" image.tar
- name: Verify
run: |
regctl manifest get "$IMAGE:${{ steps.tag.outputs.value }}" >/dev/null
printf 'Pushed %s:%s\n' "$IMAGE" "${{ steps.tag.outputs.value }}"