fix(ci): log in to registry for manifest-only main pushes
ci / lint-compose (push) Successful in 11s
ci / lint-actionlint (push) Successful in 6s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 8s
ci / lint-yaml (push) Successful in 13s
ci / lint-dockerfiles (push) Successful in 8s
ci / validate (push) Successful in 9s
renovate-ci / validate-renovate (push) Successful in 10s
ci / build (push) Successful in 27s
ci / lint-compose (push) Successful in 11s
ci / lint-actionlint (push) Successful in 6s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 8s
ci / lint-yaml (push) Successful in 13s
ci / lint-dockerfiles (push) Successful in 8s
ci / validate (push) Successful in 9s
renovate-ci / validate-renovate (push) Successful in 10s
ci / build (push) Successful in 27s
The pin step writes manifest PUTs on every main push, but login was gated on services != ''. Manifest-only pushes skipped login and pushed anonymously (401); this only worked before via a stale persistent login on the old runner.
This commit is contained in:
1 parent
4856348a6e
commit
e56662194b
1 file changed
+5
-1
@@ -390,7 +390,11 @@ jobs:
|
|||||||
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- name: Log in to registry
|
- name: Log in to registry
|
||||||
if: steps.services.outputs.services != ''
|
# The pin step below also writes (manifest PUTs), and it runs on every
|
||||||
|
# main push — including manifest-only ones where services is empty. A
|
||||||
|
# stale persistent login on the old runner used to mask this; a clean
|
||||||
|
# runner pushes anonymously and gets 401.
|
||||||
|
if: steps.services.outputs.services != '' || github.ref_name == 'main'
|
||||||
shell: bash
|
shell: bash
|
||||||
# Through env, not by substitution into the script. A secret written
|
# Through env, not by substitution into the script. A secret written
|
||||||
# into a run: block is pasted into the shell source before bash parses
|
# into a run: block is pasted into the shell source before bash parses
|
||||||
|
|||||||
Reference in new issue
Block a user