diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index fda8f35..3f8e03e 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -104,42 +104,46 @@ jobs: - name: Upload deb packages to registry env: - GITEA_TOKEN: ${{ gitea.token }} + GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }} run: | + set -euo pipefail + if [ -z "${GITEA_PUBLISH_TOKEN}" ]; then + echo "::error::GITEA_PACKAGE_TOKEN repository secret is not configured" + exit 1 + fi VERSION=${{ steps.version.outputs.version }} DEB="fenris_${VERSION}_amd64.deb" for CODENAME in bookworm jammy noble; do - curl --fail -X PUT \ - -H "Authorization: token ${GITEA_TOKEN}" \ + curl --fail --user "xavierk:${GITEA_PUBLISH_TOKEN}" -X PUT \ -T "dist/${DEB}" \ "https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/upload" done - name: Upload RPM to registry env: - GITEA_TOKEN: ${{ gitea.token }} + GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }} run: | + set -euo pipefail VERSION=${{ steps.version.outputs.version }} RPM="fenris-${VERSION}-1.x86_64.rpm" - curl --fail -X PUT \ - -H "Authorization: token ${GITEA_TOKEN}" \ + curl --fail --user "xavierk:${GITEA_PUBLISH_TOKEN}" -X PUT \ -T "dist/${RPM}" \ "https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/upload" - name: Create Gitea release env: - GITEA_TOKEN: ${{ gitea.token }} + GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} # Check if release already exists (idempotent re-runs) EXISTING=$(curl -s -o /dev/null -w '%{http_code}' \ - -H "Authorization: token ${GITEA_TOKEN}" \ + -H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}") if [ "$EXISTING" = "200" ]; then echo "Release v${VERSION} already exists, skipping creation" else curl --fail -X POST \ - -H "Authorization: token ${GITEA_TOKEN}" \ + -H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \ -H "Content-Type: application/json" \ -d "{\"tag_name\":\"v${VERSION}\",\"name\":\"v${VERSION}\"}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases" @@ -147,12 +151,12 @@ jobs: - name: Attach artifacts to release env: - GITEA_TOKEN: ${{ gitea.token }} + GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} # Get release ID for this tag RELEASE_ID=$(curl -s \ - -H "Authorization: token ${GITEA_TOKEN}" \ + -H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}" \ | python3 -c "import sys,json; print(json.load(sys.stdin)['id'])") # Attach deb, rpm, and clearsigned checksums @@ -160,7 +164,7 @@ jobs: "dist/fenris-${VERSION}-1.x86_64.rpm" \ "dist/SHA256SUMS.asc"; do curl --fail -X POST \ - -H "Authorization: token ${GITEA_TOKEN}" \ + -H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \ -F "attachment=@${FILE}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/${RELEASE_ID}/assets" done