dfritz 536765f5b9 Stop optional image pruning after failed Tea login setup
Guard failed cleanup login setup before dependent package operations; preserve successful and optional cleanup semantics. Required contract CI 20382 passed. Exact task-specific Human review-count exception is recorded on t-c1070dtgpqqy; official architect review 8504 approved this head. No authentication repair, tag movement or consumer activation.

Authored-By: Codex (GPT-5) <noreply@openai.com>
2026-10-09 20:06:21 +00:00

action/image-push

Composite Gitea Action that pushes a locally-built image to code.fritzlab.net and prunes old numeric tags via the Gitea package API.

Pair with action/image-build — image-build loads the image to the runner's local Docker daemon, image-push uploads it.

Usage

- uses: actions/checkout@v4
- uses: https://code.fritzlab.net/action/image-build@v1
  with:
    image: code.fritzlab.net/fritzlab/chrony
- uses: https://code.fritzlab.net/action/image-push@v1
  with:
    image: code.fritzlab.net/fritzlab/chrony
    token: ${{ secrets.CI_BOT_TOKEN }}
    org: fritzlab
    name: chrony

Inputs

Name Required Default Description
image yes — Full image name without tag.
tag no github.run_number Tag to push (must already exist locally).
token yes — CI_BOT_TOKEN — registry login + cleanup API.
org yes — Gitea org for package API (fritzlab, dns).
name yes — Package name as registered in the registry.
latest no true Also push a :latest tag.
prune no true Prune old numeric registry tags. Set false for retained or independently pinned artifacts.
keep no 3 Numeric tags to retain. Older are deleted.

Behavior

  1. docker login code.fritzlab.net as ci-bot.
  2. docker push <image>:<tag>.
  3. If latest=true, also docker push <image>:latest.
  4. If prune=true, list numeric tags from Gitea package API, keep the newest keep, delete the rest. Failures here do not fail the workflow (continue-on-error: true).

Cleanup first sets up its existing Tea login. If that setup fails, the optional prune step exits with a fixed login_setup warning and does not list or delete packages, even if a previous login is available. Login output remains suppressed to avoid exposing credentials or configuration. This identifies the failing stage, not the underlying authentication or configuration cause; it does not repair login setup or change the successful cleanup's targets or retention.

prune accepts only the strings true and false; invalid input fails before registry login or push. With false, remote package listing and deletion are skipped. Image upload and local Docker cleanup remain unchanged. The action does not discover deployment pins; owners choosing pruning must account for that retention contract.

Run python3 -m unittest discover -s tests with the pinned test dependencies in tests/requirements.txt. Tests inspect the composite action, execute its credential-free validation step, and exercise the prune shell with a fake Tea client and disposable configuration. No real login, registry operation, or package deletion runs.

S
Description
fritzlab composite action: image-push
Readme
43 KiB
0 Stars 9 Watchers 0 Forks
Languages
Python 100%