Record the verified CI path and its token requirement
build / Build and push image (push) Successful in 30s
build / Build and push image (push) Successful in 30s
The registry rejects the automatic token, so the workflow needs a personal access token scoped to package read and write, and the runner label must match one the forge actually has. Both cost a failed run to discover.
This commit is contained in:
@@ -29,6 +29,12 @@ Until it is fixed, this image builds and pushes correctly but produces a sandbox
|
||||
none of its contents. **Use `mise run ai:sbx -- setup` instead** — it installs the same
|
||||
configuration and plugins into a stock sandbox at runtime, and works on 0.37.x today.
|
||||
|
||||
The pipeline itself is verified. CI builds and publishes on every push to `main` and
|
||||
every tag, and the published image pulls and contains what it should: 17 enabled
|
||||
plugins, mise, the hooks and skills, and no credentials or transcripts in any layer.
|
||||
What is unverified is the only thing that matters at runtime — whether a sandbox
|
||||
created from it sees any of that — and it will not until #366 is fixed.
|
||||
|
||||
## What the image contains
|
||||
|
||||
| Path | Source |
|
||||
@@ -70,10 +76,21 @@ regctl image import git.mroberts.dev/mroberts/claude-sbx:v1 image.tar
|
||||
|
||||
Plain `ubi:regclient/regclient` installs `regbot` rather than `regctl`; the `matching`
|
||||
filter above picks the right asset. `.gitea/workflows/build.yml` does the same on tag
|
||||
pushes and on `main`, authenticating with the automatic `GITEA_TOKEN`.
|
||||
pushes and on `main`.
|
||||
|
||||
Pulls are unaffected by the Cloudflare limit, which caps uploads only.
|
||||
|
||||
### CI authentication
|
||||
|
||||
The workflow authenticates with a `REGISTRY_TOKEN` secret holding a personal access
|
||||
token scoped to **package: Read and Write**, and nothing else. The automatic
|
||||
`GITEA_TOKEN` does not work: the package registry rejects it as `unauthorized`, and
|
||||
adding `permissions: packages: write` to the job changes nothing.
|
||||
|
||||
The job runs on `runs-on: linux`, matching the self-hosted runner's label. There is no
|
||||
`ubuntu-latest` runner on this forge, and a workflow naming one is discarded silently —
|
||||
no queued run, no error, nothing in the Actions tab.
|
||||
|
||||
## Consuming
|
||||
|
||||
```toml
|
||||
|
||||
Reference in New Issue
Block a user