spike(ci): install a docker CLI so the registry probe can get past login (#237) #244
@@ -54,20 +54,57 @@ jobs:
|
||||
echo "--- disk ---"
|
||||
df -h / | tail -1
|
||||
|
||||
# Reported as a boolean, never printed. If this says NO, the login below
|
||||
# will fail and the fix is to add the secret, not to change the workflow.
|
||||
# Iteration 2. The first run answered Question 1 with "no": the job
|
||||
# container has no `docker` binary and login died with exit 127. What it
|
||||
# also showed is that /var/run/docker.sock IS mounted, so the daemon is
|
||||
# reachable and only the client is missing — which is a gap this step can
|
||||
# close without changing how the runner itself is configured.
|
||||
#
|
||||
# The static binary rather than apt: it is one download with no package
|
||||
# index to refresh and no repository to add, and only the CLI is wanted.
|
||||
# The daemon already exists on the other side of that socket.
|
||||
#
|
||||
# Not continue-on-error. If this fails there is nothing left to measure,
|
||||
# and a clear failure here is more useful than three skipped steps.
|
||||
- name: Install the docker CLI, since the runner has none
|
||||
run: |
|
||||
DOCKER_VERSION=27.3.1
|
||||
# Resolved rather than assumed. The NAS's architecture has never been
|
||||
# confirmed anywhere in this repository, and hardcoding x86_64 would
|
||||
# waste a whole run on a machine that everything else queues behind.
|
||||
case "$(uname -m)" in
|
||||
x86_64) DOCKER_ARCH=x86_64 ;;
|
||||
aarch64|arm64) DOCKER_ARCH=aarch64 ;;
|
||||
*) echo "unsupported architecture $(uname -m) — no static docker build for it"; exit 1 ;;
|
||||
esac
|
||||
echo "runner architecture: $(uname -m) -> downloading $DOCKER_ARCH"
|
||||
curl -fsSL "https://download.docker.com/linux/static/stable/${DOCKER_ARCH}/docker-${DOCKER_VERSION}.tgz" -o /tmp/docker.tgz
|
||||
tar -xzf /tmp/docker.tgz -C /tmp
|
||||
install -m 0755 /tmp/docker/docker /usr/local/bin/docker
|
||||
docker version
|
||||
echo "--- can it reach the daemon through the socket? ---"
|
||||
docker info --format 'server {{.ServerVersion}}, {{.Driver}}, {{.Architecture}}'
|
||||
|
||||
# REGISTRY_TOKEN, not GITEA_TOKEN. Iteration 2 established that the token
|
||||
# Actions injects automatically is scoped for the repository API and is
|
||||
# refused by the package registry — the login failed with a 401, not a
|
||||
# certificate error, so everything except the credential was already
|
||||
# working. This is a personal access token carrying write:package.
|
||||
#
|
||||
# Reported as a boolean and never printed. If this says EMPTY the fix is
|
||||
# the secret, not the workflow.
|
||||
- name: Is a token available?
|
||||
continue-on-error: true
|
||||
run: |
|
||||
if [ -n "${{ secrets.GITEA_TOKEN }}" ]; then
|
||||
echo "GITEA_TOKEN is present"
|
||||
if [ -n "${{ secrets.REGISTRY_TOKEN }}" ]; then
|
||||
echo "REGISTRY_TOKEN is present"
|
||||
else
|
||||
echo "GITEA_TOKEN is EMPTY — add a repo secret with package write scope"
|
||||
echo "REGISTRY_TOKEN is EMPTY — add a repo secret holding a PAT with write:package"
|
||||
fi
|
||||
|
||||
- name: Question 2a — log in to the registry
|
||||
run: |
|
||||
echo "${{ secrets.GITEA_TOKEN }}" \
|
||||
echo "${{ secrets.REGISTRY_TOKEN }}" \
|
||||
| docker login "$REGISTRY" -u "${{ github.actor }}" --password-stdin
|
||||
|
||||
# A trivial image first, deliberately. It separates "can this runner build
|
||||
|
||||
Reference in New Issue
Block a user