ci: use PAT for package publication
This commit is contained in:
@@ -104,42 +104,46 @@ jobs:
|
|||||||
|
|
||||||
- name: Upload deb packages to registry
|
- name: Upload deb packages to registry
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ gitea.token }}
|
GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
if [ -z "${GITEA_PUBLISH_TOKEN}" ]; then
|
||||||
|
echo "::error::GITEA_PACKAGE_TOKEN repository secret is not configured"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
VERSION=${{ steps.version.outputs.version }}
|
VERSION=${{ steps.version.outputs.version }}
|
||||||
DEB="fenris_${VERSION}_amd64.deb"
|
DEB="fenris_${VERSION}_amd64.deb"
|
||||||
for CODENAME in bookworm jammy noble; do
|
for CODENAME in bookworm jammy noble; do
|
||||||
curl --fail -X PUT \
|
curl --fail --user "xavierk:${GITEA_PUBLISH_TOKEN}" -X PUT \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
|
||||||
-T "dist/${DEB}" \
|
-T "dist/${DEB}" \
|
||||||
"https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/upload"
|
"https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/upload"
|
||||||
done
|
done
|
||||||
|
|
||||||
- name: Upload RPM to registry
|
- name: Upload RPM to registry
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ gitea.token }}
|
GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
VERSION=${{ steps.version.outputs.version }}
|
VERSION=${{ steps.version.outputs.version }}
|
||||||
RPM="fenris-${VERSION}-1.x86_64.rpm"
|
RPM="fenris-${VERSION}-1.x86_64.rpm"
|
||||||
curl --fail -X PUT \
|
curl --fail --user "xavierk:${GITEA_PUBLISH_TOKEN}" -X PUT \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
|
||||||
-T "dist/${RPM}" \
|
-T "dist/${RPM}" \
|
||||||
"https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/upload"
|
"https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/upload"
|
||||||
|
|
||||||
- name: Create Gitea release
|
- name: Create Gitea release
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ gitea.token }}
|
GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
VERSION=${{ steps.version.outputs.version }}
|
VERSION=${{ steps.version.outputs.version }}
|
||||||
# Check if release already exists (idempotent re-runs)
|
# Check if release already exists (idempotent re-runs)
|
||||||
EXISTING=$(curl -s -o /dev/null -w '%{http_code}' \
|
EXISTING=$(curl -s -o /dev/null -w '%{http_code}' \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
||||||
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}")
|
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}")
|
||||||
if [ "$EXISTING" = "200" ]; then
|
if [ "$EXISTING" = "200" ]; then
|
||||||
echo "Release v${VERSION} already exists, skipping creation"
|
echo "Release v${VERSION} already exists, skipping creation"
|
||||||
else
|
else
|
||||||
curl --fail -X POST \
|
curl --fail -X POST \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json" \
|
||||||
-d "{\"tag_name\":\"v${VERSION}\",\"name\":\"v${VERSION}\"}" \
|
-d "{\"tag_name\":\"v${VERSION}\",\"name\":\"v${VERSION}\"}" \
|
||||||
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases"
|
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases"
|
||||||
@@ -147,12 +151,12 @@ jobs:
|
|||||||
|
|
||||||
- name: Attach artifacts to release
|
- name: Attach artifacts to release
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ gitea.token }}
|
GITEA_PUBLISH_TOKEN: ${{ secrets.GITEA_PACKAGE_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
VERSION=${{ steps.version.outputs.version }}
|
VERSION=${{ steps.version.outputs.version }}
|
||||||
# Get release ID for this tag
|
# Get release ID for this tag
|
||||||
RELEASE_ID=$(curl -s \
|
RELEASE_ID=$(curl -s \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
||||||
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}" \
|
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}" \
|
||||||
| python3 -c "import sys,json; print(json.load(sys.stdin)['id'])")
|
| python3 -c "import sys,json; print(json.load(sys.stdin)['id'])")
|
||||||
# Attach deb, rpm, and clearsigned checksums
|
# Attach deb, rpm, and clearsigned checksums
|
||||||
@@ -160,7 +164,7 @@ jobs:
|
|||||||
"dist/fenris-${VERSION}-1.x86_64.rpm" \
|
"dist/fenris-${VERSION}-1.x86_64.rpm" \
|
||||||
"dist/SHA256SUMS.asc"; do
|
"dist/SHA256SUMS.asc"; do
|
||||||
curl --fail -X POST \
|
curl --fail -X POST \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
-H "Authorization: token ${GITEA_PUBLISH_TOKEN}" \
|
||||||
-F "attachment=@${FILE}" \
|
-F "attachment=@${FILE}" \
|
||||||
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/${RELEASE_ID}/assets"
|
"https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/${RELEASE_ID}/assets"
|
||||||
done
|
done
|
||||||
|
|||||||
Reference in New Issue
Block a user