fix(ci): use the Actions token, not REGISTRY_TOKEN, to read the E2E commit status
PR Checks / Frontend Typecheck + Tests (pull_request) Successful in 1m5s
PR Checks / Backend Smoke (pull_request) Successful in 7s
PR Checks / Build Backend (no push) (pull_request) Successful in 11s
PR Checks / Build Frontend (no push) (pull_request) Successful in 47s
PR Checks / Build Pipeline (no push) (pull_request) Successful in 10s
PR Checks / AI Code Review (Claude) (pull_request) Successful in 36s
PR Checks / Frontend Typecheck + Tests (pull_request) Successful in 1m5s
PR Checks / Backend Smoke (pull_request) Successful in 7s
PR Checks / Build Backend (no push) (pull_request) Successful in 11s
PR Checks / Build Frontend (no push) (pull_request) Successful in 47s
PR Checks / Build Pipeline (no push) (pull_request) Successful in 10s
PR Checks / AI Code Review (Claude) (pull_request) Successful in 36s
Promotion's 'Verify the staging E2E gate' step called the Gitea commit-status API with REGISTRY_TOKEN, which has container-registry scope but no repository scope — so the API returned 403 and promotion failed. Switch to the built-in GITHUB_TOKEN (repo read scope), matching how pr-checks.yml already authenticates to the Gitea API. REGISTRY_TOKEN is still used for the docker registry login, which is its correct scope. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0146VHeLAWjDVE2B5uU67jCB
This commit is contained in:
@@ -67,9 +67,12 @@ jobs:
|
|||||||
echo "Promoting $FULL_SHA (images tagged $SHORT_SHA)"
|
echo "Promoting $FULL_SHA (images tagged $SHORT_SHA)"
|
||||||
|
|
||||||
- name: Verify the staging E2E gate passed for this commit
|
- name: Verify the staging E2E gate passed for this commit
|
||||||
|
# Use the built-in Actions token (GITHUB_TOKEN is the documented name;
|
||||||
|
# it carries repository read scope), NOT REGISTRY_TOKEN — the registry
|
||||||
|
# token has no repo scope, so the commit-status API returns 403.
|
||||||
run: |
|
run: |
|
||||||
STATUS_JSON=$(curl -fsS \
|
STATUS_JSON=$(curl -fsS \
|
||||||
-H "Authorization: token ${{ secrets.REGISTRY_TOKEN }}" \
|
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||||
"https://${REGISTRY}/api/v1/repos/${{ gitea.repository }}/commits/${{ steps.resolve.outputs.full }}/status")
|
"https://${REGISTRY}/api/v1/repos/${{ gitea.repository }}/commits/${{ steps.resolve.outputs.full }}/status")
|
||||||
echo "$STATUS_JSON" | python3 -c "
|
echo "$STATUS_JSON" | python3 -c "
|
||||||
import json, sys
|
import json, sys
|
||||||
|
|||||||
Reference in New Issue
Block a user