ci: publish the release image on the forge's registry #5

Merged
thibault merged 1 commit from ci/forgejo-image into 0.2 2026-10-08 18:44:21 +02:00
Owner

GHCR is out of reach while the GitHub account is hidden.

  • .forgejo/workflows/image.yml: on a PR into main, builds both binaries (scripts/deploy.sh, cross with podman) and a multi-arch manifest with podman; on push to main, publishes git.thibot.fr/thibault/plankton:latest and :<version>, then signs the deploy hook call to the Pi.
  • Secrets: REGISTRY_TOKEN (package write; the automatic token may not publish packages, checked with a probe) and DEPLOY_HOOK_SECRET. Missing ones only warn.
  • compose.yaml pulls the forge image; Dockerfile label and update.sh prune filter follow.
  • README: CI section (forge, PC runner in host mode), deployment wording.

Built locally with the same steps: glibc 2.34 on both targets, manifest arm64 + amd64.

🤖 Generated with Claude Code

GHCR is out of reach while the GitHub account is hidden. - `.forgejo/workflows/image.yml`: on a PR into main, builds both binaries (scripts/deploy.sh, cross with podman) and a multi-arch manifest with podman; on push to main, publishes `git.thibot.fr/thibault/plankton:latest` and `:<version>`, then signs the deploy hook call to the Pi. - Secrets: `REGISTRY_TOKEN` (package write; the automatic token may not publish packages, checked with a probe) and `DEPLOY_HOOK_SECRET`. Missing ones only warn. - compose.yaml pulls the forge image; Dockerfile label and update.sh prune filter follow. - README: CI section (forge, PC runner in host mode), deployment wording. Built locally with the same steps: glibc 2.34 on both targets, manifest arm64 + amd64. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ci: publish the release image on the forge's registry
All checks were successful
CI / web (pull_request) Successful in 6s
CI / test (pull_request) Successful in 26s
33f31f0c94
GitHub's registry is out of reach while the account is hidden. The image
is now built on the PC runner (both binaries in one job, podman manifest)
and published as git.thibot.fr/thibault/plankton, which compose.yaml now
pulls. Publishing needs a REGISTRY_TOKEN secret with the package
permission: the run's automatic token may not publish packages. Without
it, or without DEPLOY_HOOK_SECRET, the step warns and does nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01947SGTYxD1CJLsk2PcULRA
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thibault/plankton!5
No description provided.