diff --git a/.gitea/workflows/spike-registry.yml b/.gitea/workflows/spike-registry.yml index 3eeb306..d6f48fb 100644 --- a/.gitea/workflows/spike-registry.yml +++ b/.gitea/workflows/spike-registry.yml @@ -54,20 +54,57 @@ jobs: echo "--- disk ---" df -h / | tail -1 - # Reported as a boolean, never printed. If this says NO, the login below - # will fail and the fix is to add the secret, not to change the workflow. + # Iteration 2. The first run answered Question 1 with "no": the job + # container has no `docker` binary and login died with exit 127. What it + # also showed is that /var/run/docker.sock IS mounted, so the daemon is + # reachable and only the client is missing — which is a gap this step can + # close without changing how the runner itself is configured. + # + # The static binary rather than apt: it is one download with no package + # index to refresh and no repository to add, and only the CLI is wanted. + # The daemon already exists on the other side of that socket. + # + # Not continue-on-error. If this fails there is nothing left to measure, + # and a clear failure here is more useful than three skipped steps. + - name: Install the docker CLI, since the runner has none + run: | + DOCKER_VERSION=27.3.1 + # Resolved rather than assumed. The NAS's architecture has never been + # confirmed anywhere in this repository, and hardcoding x86_64 would + # waste a whole run on a machine that everything else queues behind. + case "$(uname -m)" in + x86_64) DOCKER_ARCH=x86_64 ;; + aarch64|arm64) DOCKER_ARCH=aarch64 ;; + *) echo "unsupported architecture $(uname -m) — no static docker build for it"; exit 1 ;; + esac + echo "runner architecture: $(uname -m) -> downloading $DOCKER_ARCH" + curl -fsSL "https://download.docker.com/linux/static/stable/${DOCKER_ARCH}/docker-${DOCKER_VERSION}.tgz" -o /tmp/docker.tgz + tar -xzf /tmp/docker.tgz -C /tmp + install -m 0755 /tmp/docker/docker /usr/local/bin/docker + docker version + echo "--- can it reach the daemon through the socket? ---" + docker info --format 'server {{.ServerVersion}}, {{.Driver}}, {{.Architecture}}' + + # REGISTRY_TOKEN, not GITEA_TOKEN. Iteration 2 established that the token + # Actions injects automatically is scoped for the repository API and is + # refused by the package registry — the login failed with a 401, not a + # certificate error, so everything except the credential was already + # working. This is a personal access token carrying write:package. + # + # Reported as a boolean and never printed. If this says EMPTY the fix is + # the secret, not the workflow. - name: Is a token available? continue-on-error: true run: | - if [ -n "${{ secrets.GITEA_TOKEN }}" ]; then - echo "GITEA_TOKEN is present" + if [ -n "${{ secrets.REGISTRY_TOKEN }}" ]; then + echo "REGISTRY_TOKEN is present" else - echo "GITEA_TOKEN is EMPTY — add a repo secret with package write scope" + echo "REGISTRY_TOKEN is EMPTY — add a repo secret holding a PAT with write:package" fi - name: Question 2a — log in to the registry run: | - echo "${{ secrets.GITEA_TOKEN }}" \ + echo "${{ secrets.REGISTRY_TOKEN }}" \ | docker login "$REGISTRY" -u "${{ github.actor }}" --password-stdin # A trivial image first, deliberately. It separates "can this runner build