Harden the build workflow and grant package write
build / Build and push image (push) Failing after 36s

The v1.0.1 tag claimed this work but did not contain it: the edits were still
in the working copy when main was moved and pushed. This is that change.

The run against v1.0.1 reached the registry and failed with 'unauthorized'.
The automatic token cannot write packages without the job asking for it, so
the job now requests packages: write and nothing wider.

actions/checkout is pinned to a commit rather than a tag, at v4.4.0 rather than
the current v7.0.1, which declares node24 that act_runner does not provide.
regctl is pinned to a release instead of tracking latest. Every expansion moves
into env so nothing interpolates into a shell body.

Clean under actionlint and zizmor --persona=auditor. .shush.toml preserves the
comments those linters require, which the comment hook was otherwise removing.
This commit is contained in:
2026-07-31 08:55:19 -05:00
parent b79bf35e70
commit 5c0a7263e4
2 changed files with 48 additions and 12 deletions
+39 -12
View File
@@ -5,53 +5,80 @@ on:
branches: [main]
tags: ['v*']
permissions:
contents: read
concurrency:
group: build-${{ github.ref }}
cancel-in-progress: true
env:
REGISTRY: git.mroberts.dev
IMAGE: git.mroberts.dev/mroberts/claude-sbx
REGCTL_VERSION: v0.11.5
jobs:
build:
name: Build and push image
runs-on: linux
permissions:
contents: read
packages: write # regctl pushes the image to the registry (zizmor)
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Install regctl
run: |
mkdir -p "$HOME/.local/bin"
curl -fsSL -o "$HOME/.local/bin/regctl" \
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
"https://github.com/regclient/regclient/releases/download/${REGCTL_VERSION}/regctl-linux-amd64"
chmod +x "$HOME/.local/bin/regctl"
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
- name: Resolve tag
id: tag
env:
REF: ${{ github.ref }}
run: |
if [[ "$GITHUB_REF" == refs/tags/* ]]; then
printf 'value=%s\n' "${GITHUB_REF#refs/tags/}" >>"$GITHUB_OUTPUT"
if [[ "$REF" == refs/tags/* ]]; then
printf 'value=%s\n' "${REF#refs/tags/}" >>"$GITHUB_OUTPUT"
else
printf 'value=edge\n' >>"$GITHUB_OUTPUT"
fi
- name: Build
run: docker build -t "$IMAGE:${{ steps.tag.outputs.value }}" .
env:
TAG: ${{ steps.tag.outputs.value }}
run: docker build -t "$IMAGE:$TAG" .
- name: Export image
run: docker save "$IMAGE:${{ steps.tag.outputs.value }}" -o image.tar
env:
TAG: ${{ steps.tag.outputs.value }}
run: docker save "$IMAGE:$TAG" -o image.tar
- name: Push
env:
TAG: ${{ steps.tag.outputs.value }}
REGISTRY_USER: ${{ github.actor }}
# zizmor: ignore[secrets-outside-env]
REGISTRY_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
regctl registry login "$REGISTRY" \
--user "${{ github.actor }}" \
--pass-stdin <<<"${{ secrets.GITEA_TOKEN }}"
printf '%s' "$REGISTRY_TOKEN" |
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin
regctl registry set "$REGISTRY" \
--blob-chunk 50000000 \
--blob-max 50000000
regctl image import "$IMAGE:${{ steps.tag.outputs.value }}" image.tar
regctl image import "$IMAGE:$TAG" image.tar
- name: Verify
env:
TAG: ${{ steps.tag.outputs.value }}
run: |
regctl manifest get "$IMAGE:${{ steps.tag.outputs.value }}" >/dev/null
printf 'Pushed %s:%s\n' "$IMAGE" "${{ steps.tag.outputs.value }}"
regctl manifest get "$IMAGE:$TAG" >/dev/null
printf 'Pushed %s:%s\n' "$IMAGE" "$TAG"