Set up vicoli-oss, move the repo, and store the package token #5

Closed
opened 2026-09-30 13:14:53 +00:00 by piscis · 3 comments
Owner

What to build

The human-only setup that publishing and bumps need. (The Renovate bot allowlist step was dropped: the Pin now records which Upstream Version the Rebuild counts against, so Renovate needs no post-upgrade command. See #16 and ADR 0003.) The decisions behind it are in ADR 0004 and the grilling comment on this issue.

  1. Create the public org vicoli-oss, visibility public, with member visibility left private (the default). Teams:
    • Owners: piscis.
    • Bots: dockhand and renovatebot, with write on code, pulls, issues, packages and actions. Do not give it access to all repos; add docker-forgejo-mcp explicitly.
  2. Transfer vicoli/docker-forgejo-mcp to vicoli-oss and make it public. Issues, PRs and history move with it, and Forgejo redirects the old path.
  3. Package token: create a token for dockhand with write:package only, and store it as the repo-level Actions secret PACKAGE_TOKEN on vicoli-oss/docker-forgejo-mcp. Workflows log in as username: dockhand.

Acceptance criteria

  • vicoli-oss exists and is public: curl -sS -o /dev/null -w '%{http_code}' https://code.vicoli.de/api/v1/orgs/vicoli-oss returns 200 without a token
  • All vicoli packages are still private (the org is still private)
  • The repo lives at vicoli-oss/docker-forgejo-mcp and is public
  • dockhand and renovatebot are in the vicoli-oss Bots team, which has access to this repo only
  • PACKAGE_TOKEN (dockhand, write:package only) is stored as a repo Actions secret

The actual anonymous docker pull is checked in #7, once an Image exists.

Blocked by

  • None (can start immediately)

Context: see GLOSSARY.md (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and docs/adr/ (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public org vicoli-oss).

## What to build The human-only setup that publishing and bumps need. (The Renovate bot allowlist step was dropped: the Pin now records which Upstream Version the Rebuild counts against, so Renovate needs no post-upgrade command. See #16 and ADR 0003.) The decisions behind it are in ADR 0004 and the grilling comment on this issue. 1. **Create the public org `vicoli-oss`**, visibility public, with member visibility left private (the default). Teams: - Owners: `piscis`. - `Bots`: `dockhand` and `renovatebot`, with write on code, pulls, issues, packages and actions. Do **not** give it access to all repos; add `docker-forgejo-mcp` explicitly. 2. **Transfer `vicoli/docker-forgejo-mcp` to `vicoli-oss` and make it public.** Issues, PRs and history move with it, and Forgejo redirects the old path. 3. **Package token:** create a token for `dockhand` with `write:package` only, and store it as the repo-level Actions secret `PACKAGE_TOKEN` on `vicoli-oss/docker-forgejo-mcp`. Workflows log in as `username: dockhand`. ## Acceptance criteria - [x] `vicoli-oss` exists and is public: `curl -sS -o /dev/null -w '%{http_code}' https://code.vicoli.de/api/v1/orgs/vicoli-oss` returns `200` without a token - [x] All `vicoli` packages are still private (the org is still private) - [x] The repo lives at `vicoli-oss/docker-forgejo-mcp` and is public - [x] `dockhand` and `renovatebot` are in the `vicoli-oss` `Bots` team, which has access to this repo only - [x] `PACKAGE_TOKEN` (`dockhand`, `write:package` only) is stored as a repo Actions secret The actual anonymous `docker pull` is checked in #7, once an Image exists. ## Blocked by - None (can start immediately) Context: see `GLOSSARY.md` (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and `docs/adr/` (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public org `vicoli-oss`).
piscis changed title from Set up the bot user, registry token and package visibility to Set up vicoli-oss, move the repo, and store the package token 2026-09-30 13:47:16 +00:00
Author
Owner

Grilling outcome

Decisions from grilling this issue against GLOSSARY.md and docs/adr/:

  1. Bumps go through Renovate, not a custom workflow. renovatebot already runs in the org. A regex manager updates UPSTREAM_VERSION and UPSTREAM_COMMIT in pin.env, and an allowlisted postUpgradeTasks command resets REBUILD to 1. #8 is rewritten to match.
  2. Consumers are anyone and pull anonymously (glossary updated).
  3. The secret is repo-level PACKAGE_TOKEN, following the convention in vicoli-homepage-2026.
  4. Public owner is a new org vicoli-oss. Forgejo 16 decides package visibility per owner, not per package, so making vicoli public would expose every vicoli package, including homepage-cms and homepage-web. All vicoli packages stay private (ADR 0004).
  5. dockhand pushes the Image with a write:package-only token. There's no new vicoli-bot. Workflows log in as dockhand, not github.actor.
  6. The repo is transferred to vicoli-oss and made public. A new ticket updates the references and adds an MIT LICENSE. The Image is labelled GPL-3.0 (Upstream's license).
  7. Teams in vicoli-oss mirror vicoli: Owners (piscis), and Bots (dockhand and renovatebot) scoped to this repo.

Facts checked:

  • Runners are registered for the whole instance, so they keep working after the move.
  • Registration on code.vicoli.de is disabled.
  • A PR opened with a user's token triggers pull_request workflows; the automatic workflow token doesn't.
## Grilling outcome Decisions from grilling this issue against `GLOSSARY.md` and `docs/adr/`: 1. **Bumps go through Renovate**, not a custom workflow. `renovatebot` already runs in the org. A regex manager updates `UPSTREAM_VERSION` and `UPSTREAM_COMMIT` in `pin.env`, and an allowlisted `postUpgradeTasks` command resets `REBUILD` to 1. #8 is rewritten to match. 2. **Consumers are anyone** and pull anonymously (glossary updated). 3. **The secret is repo-level `PACKAGE_TOKEN`**, following the convention in `vicoli-homepage-2026`. 4. **Public owner is a new org `vicoli-oss`.** Forgejo 16 decides package visibility per owner, not per package, so making `vicoli` public would expose every `vicoli` package, including `homepage-cms` and `homepage-web`. All `vicoli` packages stay private (ADR 0004). 5. **`dockhand` pushes the Image** with a `write:package`-only token. There's no new `vicoli-bot`. Workflows log in as `dockhand`, not `github.actor`. 6. **The repo is transferred to `vicoli-oss` and made public.** A new ticket updates the references and adds an MIT `LICENSE`. The Image is labelled GPL-3.0 (Upstream's license). 7. **Teams in `vicoli-oss`** mirror `vicoli`: Owners (`piscis`), and `Bots` (`dockhand` and `renovatebot`) scoped to this repo. Facts checked: - Runners are registered for the whole instance, so they keep working after the move. - Registration on `code.vicoli.de` is disabled. - A PR opened with a user's token triggers `pull_request` workflows; the automatic workflow token doesn't.
Author
Owner

Status check: every acceptance criterion is verified via the API (org public, vicoli still private, repo moved and public, Bots team with dockhand and renovatebot scoped to this repo, PACKAGE_TOKEN present). I can't see the token's account or scopes: it should be dockhand with write:package only. The Renovate allowlist step is dropped in favour of #16. Note: the Bots team's overall permission shows read because its units are mixed. If the first Renovate push or dockhand package push gets a 403, set every unit to write.

Status check: every acceptance criterion is verified via the API (org public, `vicoli` still private, repo moved and public, `Bots` team with `dockhand` and `renovatebot` scoped to this repo, `PACKAGE_TOKEN` present). I can't see the token's account or scopes: it should be `dockhand` with `write:package` only. The Renovate allowlist step is dropped in favour of #16. Note: the `Bots` team's overall permission shows `read` because its units are mixed. If the first Renovate push or `dockhand` package push gets a 403, set every unit to write.
Author
Owner

PACKAGE_TOKEN confirmed in place (dockhand, write:package). All acceptance criteria met; closing. #14, #7 and #8 are no longer blocked by this.

`PACKAGE_TOKEN` confirmed in place (`dockhand`, `write:package`). All acceptance criteria met; closing. #14, #7 and #8 are no longer blocked by this.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
vicoli-oss/docker-forgejo-mcp#5
No description provided.