Set up vicoli-oss, move the repo, and store the package token #5
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
#7 Publish the Image on push to main
vicoli-oss/docker-forgejo-mcp
#8 Renovate opens bump PRs for new Upstream Versions
vicoli-oss/docker-forgejo-mcp
#14 Point the repo at vicoli-oss and add an MIT license
vicoli-oss/docker-forgejo-mcp
Reference
vicoli-oss/docker-forgejo-mcp#5
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What to build
The human-only setup that publishing and bumps need. (The Renovate bot allowlist step was dropped: the Pin now records which Upstream Version the Rebuild counts against, so Renovate needs no post-upgrade command. See #16 and ADR 0003.) The decisions behind it are in ADR 0004 and the grilling comment on this issue.
vicoli-oss, visibility public, with member visibility left private (the default). Teams:piscis.Bots:dockhandandrenovatebot, with write on code, pulls, issues, packages and actions. Do not give it access to all repos; adddocker-forgejo-mcpexplicitly.vicoli/docker-forgejo-mcptovicoli-ossand make it public. Issues, PRs and history move with it, and Forgejo redirects the old path.dockhandwithwrite:packageonly, and store it as the repo-level Actions secretPACKAGE_TOKENonvicoli-oss/docker-forgejo-mcp. Workflows log in asusername: dockhand.Acceptance criteria
vicoli-ossexists and is public:curl -sS -o /dev/null -w '%{http_code}' https://code.vicoli.de/api/v1/orgs/vicoli-ossreturns200without a tokenvicolipackages are still private (the org is still private)vicoli-oss/docker-forgejo-mcpand is publicdockhandandrenovatebotare in thevicoli-ossBotsteam, which has access to this repo onlyPACKAGE_TOKEN(dockhand,write:packageonly) is stored as a repo Actions secretThe actual anonymous
docker pullis checked in #7, once an Image exists.Blocked by
Context: see
GLOSSARY.md(Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) anddocs/adr/(0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags, 0004 public orgvicoli-oss).Set up the bot user, registry token and package visibilityto Set up vicoli-oss, move the repo, and store the package tokenGrilling outcome
Decisions from grilling this issue against
GLOSSARY.mdanddocs/adr/:renovatebotalready runs in the org. A regex manager updatesUPSTREAM_VERSIONandUPSTREAM_COMMITinpin.env, and an allowlistedpostUpgradeTaskscommand resetsREBUILDto 1. #8 is rewritten to match.PACKAGE_TOKEN, following the convention invicoli-homepage-2026.vicoli-oss. Forgejo 16 decides package visibility per owner, not per package, so makingvicolipublic would expose everyvicolipackage, includinghomepage-cmsandhomepage-web. Allvicolipackages stay private (ADR 0004).dockhandpushes the Image with awrite:package-only token. There's no newvicoli-bot. Workflows log in asdockhand, notgithub.actor.vicoli-ossand made public. A new ticket updates the references and adds an MITLICENSE. The Image is labelled GPL-3.0 (Upstream's license).vicoli-ossmirrorvicoli: Owners (piscis), andBots(dockhandandrenovatebot) scoped to this repo.Facts checked:
code.vicoli.deis disabled.pull_requestworkflows; the automatic workflow token doesn't.Status check: every acceptance criterion is verified via the API (org public,
vicolistill private, repo moved and public,Botsteam withdockhandandrenovatebotscoped to this repo,PACKAGE_TOKENpresent). I can't see the token's account or scopes: it should bedockhandwithwrite:packageonly. The Renovate allowlist step is dropped in favour of #16. Note: theBotsteam's overall permission showsreadbecause its units are mixed. If the first Renovate push ordockhandpackage push gets a 403, set every unit to write.PACKAGE_TOKENconfirmed in place (dockhand,write:package). All acceptance criteria met; closing. #14, #7 and #8 are no longer blocked by this.