Emit a fixed credential-free login_setup warning and fail the optional prune step before any dependent package API calls if its existing login setup fails. Preserve successful pruning, retention, registry upload and local cleanup. Exercise the extracted prune shell with fake Tea and disposable configuration, including failed setup with a previous login and unchanged successful targets. This identifies the failed stage, not the suppressed authentication cause. Ticket: https://agenthub.fritzlab.net/t-c1070dtgpqqy Authored-By: Codex (GPT-5) <noreply@openai.com>
action/image-push
Composite Gitea Action that pushes a locally-built image to
code.fritzlab.net and prunes old numeric tags via the Gitea package API.
Pair with action/image-build — image-build loads the image to the runner's
local Docker daemon, image-push uploads it.
Usage
- uses: actions/checkout@v4
- uses: https://code.fritzlab.net/action/image-build@v1
with:
image: code.fritzlab.net/fritzlab/chrony
- uses: https://code.fritzlab.net/action/image-push@v1
with:
image: code.fritzlab.net/fritzlab/chrony
token: ${{ secrets.CI_BOT_TOKEN }}
org: fritzlab
name: chrony
Inputs
| Name | Required | Default | Description |
|---|---|---|---|
image |
yes | — | Full image name without tag. |
tag |
no | github.run_number |
Tag to push (must already exist locally). |
token |
yes | — | CI_BOT_TOKEN — registry login + cleanup API. |
org |
yes | — | Gitea org for package API (fritzlab, dns). |
name |
yes | — | Package name as registered in the registry. |
latest |
no | true |
Also push a :latest tag. |
prune |
no | true |
Prune old numeric registry tags. Set false for retained or independently pinned artifacts. |
keep |
no | 3 |
Numeric tags to retain. Older are deleted. |
Behavior
docker login code.fritzlab.netasci-bot.docker push <image>:<tag>.- If
latest=true, alsodocker push <image>:latest. - If
prune=true, list numeric tags from Gitea package API, keep the newestkeep, delete the rest. Failures here do not fail the workflow (continue-on-error: true).
Cleanup first sets up its existing Tea login. If that setup fails, the optional
prune step exits with a fixed login_setup warning and does not list or delete
packages, even if a previous login is available. Login output remains suppressed
to avoid exposing credentials or configuration. This identifies the failing
stage, not the underlying authentication or configuration cause; it does not
repair login setup or change the successful cleanup's targets or retention.
prune accepts only the strings true and false; invalid input fails before
registry login or push. With false, remote package listing and deletion are
skipped. Image upload and local Docker cleanup remain unchanged. The action does
not discover deployment pins; owners choosing pruning must account for that
retention contract.
Run python3 -m unittest discover -s tests with the pinned test dependencies in
tests/requirements.txt. Tests inspect the composite action, execute its
credential-free validation step, and exercise the prune shell with a fake Tea
client and disposable configuration. No real login, registry operation, or
package deletion runs.