ci: use RELEASE_TOKEN + publish to packages registry

- Release step now authenticates with the RELEASE_TOKEN Actions secret
  (repo write) instead of the automatic token; drop the now-unneeded
  permissions block.
- Add a step that publishes the skill zip to the Gitea generic packages
  registry (cycling-training-skill@<tag>) using the REGISTRY_TOKEN secret,
  handling 200/201/409 responses.
- README: document the registry download URL and both secrets.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqrhBhC3GEcKyaw8RTk8G6
This commit is contained in:
2026-07-20 19:26:43 -04:00
parent 6310b56f26
commit 67d2ba9f91
2 changed files with 40 additions and 12 deletions
+31 -7
View File
@@ -5,12 +5,13 @@ name: Package skill
# - Push a tag v* -> builds the zip AND attaches it to a Gitea release.
# - Run manually -> builds the zip and uploads it as a run artifact.
#
# Requirements on the Gitea side:
# Requirements on the Gitea side (already provisioned):
# * A registered Actions runner (image with bash/zip/curl, e.g. catthehacker/ubuntu).
# * Actions enabled for this repo (Settings > Actions).
# * The automatic ${{ secrets.GITHUB_TOKEN }} must have contents:write so the
# release step can create the release / upload the asset (granted via the
# `permissions` block below on Gitea >= 1.20).
# * Actions secrets:
# - RELEASE_TOKEN : token with repo write, used to create the release + upload the asset.
# - REGISTRY_TOKEN : token with package write, used to publish the zip to the
# Gitea generic packages registry.
on:
push:
@@ -26,8 +27,6 @@ on:
jobs:
package:
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
@@ -54,7 +53,7 @@ jobs:
- name: Attach zip to release
if: github.ref_type == 'tag'
env:
TOKEN: ${{ secrets.GITHUB_TOKEN }}
TOKEN: ${{ secrets.RELEASE_TOKEN }}
SERVER: ${{ github.server_url }}
REPO: ${{ github.repository }}
VERSION: ${{ steps.ver.outputs.version }}
@@ -88,3 +87,28 @@ jobs:
-F "attachment=@${ZIP}" \
"${SERVER}/api/v1/repos/${REPO}/releases/${REL_ID}/assets?name=$(basename "${ZIP}")"
echo "Attached $(basename "${ZIP}") to release ${VERSION} (id ${REL_ID})."
- name: Publish zip to Gitea packages registry
if: github.ref_type == 'tag'
env:
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
SERVER: ${{ github.server_url }}
OWNER: ${{ github.repository_owner }}
VERSION: ${{ steps.ver.outputs.version }}
run: |
set -euo pipefail
ZIP="$(ls dist/*.zip | head -1)"
FILE="$(basename "${ZIP}")"
PACKAGE="cycling-training-skill"
URL="${SERVER}/api/packages/${OWNER}/generic/${PACKAGE}/${VERSION}/${FILE}"
echo "Uploading ${FILE} to generic package ${PACKAGE}@${VERSION}"
CODE="$(curl -sS -o /tmp/reg_resp.txt -w '%{http_code}' -X PUT \
-H "Authorization: token ${REGISTRY_TOKEN}" \
--upload-file "${ZIP}" \
"${URL}")"
echo "HTTP ${CODE}"; cat /tmp/reg_resp.txt 2>/dev/null || true; echo
case "${CODE}" in
200|201) echo "Published ${FILE} to packages registry." ;;
409) echo "Version ${VERSION} already present in registry — skipping." ;;
*) echo "ERROR: registry upload failed (HTTP ${CODE})" >&2; exit 1 ;;
esac