fix(ci): image pushes read the registry secrets that exist (#1275)
ci/woodpecker/pr/ci Pipeline was successful
ci/woodpecker/pr/ci Pipeline was successful
All kaniko image steps (publish.yml build-gateway/build-ci-base/build-* and ci-image.yml build-ci-base) referenced from_secret: gitea_username / gitea_password - which do not exist at repo level - while the repo carries unused REGISTRY_USERNAME/REGISTRY_PASSWORD secrets. Result: every image push fails at kaniko's push-permission check (measured: 2482 and 2488 build-gateway 'error checking push permissions'; the same auth gap is documented in ci.yml's step-level pi install comment re ci-base). Rewire all six references to the REGISTRY_* secrets that exist. If those credentials are valid, next push pipelines go fully green behind the new verify gate; if not, the failure moves to an explicit 401 - either way the ambiguous permission error resolves into a known state.
This commit is contained in:
@@ -22,9 +22,9 @@ steps:
|
|||||||
image: gcr.io/kaniko-project/executor:debug
|
image: gcr.io/kaniko-project/executor:debug
|
||||||
environment:
|
environment:
|
||||||
REGISTRY_USER:
|
REGISTRY_USER:
|
||||||
from_secret: gitea_username
|
from_secret: REGISTRY_USERNAME
|
||||||
REGISTRY_PASS:
|
REGISTRY_PASS:
|
||||||
from_secret: gitea_password
|
from_secret: REGISTRY_PASSWORD
|
||||||
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
||||||
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
||||||
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
||||||
|
|||||||
@@ -270,9 +270,9 @@ steps:
|
|||||||
when: *image_build_when
|
when: *image_build_when
|
||||||
environment:
|
environment:
|
||||||
REGISTRY_USER:
|
REGISTRY_USER:
|
||||||
from_secret: gitea_username
|
from_secret: REGISTRY_USERNAME
|
||||||
REGISTRY_PASS:
|
REGISTRY_PASS:
|
||||||
from_secret: gitea_password
|
from_secret: REGISTRY_PASSWORD
|
||||||
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
||||||
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
||||||
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
||||||
@@ -306,9 +306,9 @@ steps:
|
|||||||
when: *main_image_build_when
|
when: *main_image_build_when
|
||||||
environment:
|
environment:
|
||||||
REGISTRY_USER:
|
REGISTRY_USER:
|
||||||
from_secret: gitea_username
|
from_secret: REGISTRY_USERNAME
|
||||||
REGISTRY_PASS:
|
REGISTRY_PASS:
|
||||||
from_secret: gitea_password
|
from_secret: REGISTRY_PASSWORD
|
||||||
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
||||||
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
||||||
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
||||||
@@ -333,9 +333,9 @@ steps:
|
|||||||
when: *main_image_build_when
|
when: *main_image_build_when
|
||||||
environment:
|
environment:
|
||||||
REGISTRY_USER:
|
REGISTRY_USER:
|
||||||
from_secret: gitea_username
|
from_secret: REGISTRY_USERNAME
|
||||||
REGISTRY_PASS:
|
REGISTRY_PASS:
|
||||||
from_secret: gitea_password
|
from_secret: REGISTRY_PASSWORD
|
||||||
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
CI_COMMIT_BRANCH: ${CI_COMMIT_BRANCH}
|
||||||
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
CI_COMMIT_TAG: ${CI_COMMIT_TAG}
|
||||||
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
CI_COMMIT_SHA: ${CI_COMMIT_SHA}
|
||||||
|
|||||||
Reference in New Issue
Block a user