Sign inSign up

docker/sbx-kit-gitea:latest

Multi-platform
Manifest digest

sha256:fcef0025c0294f99eeb0e3bd64186f285801e4ea6f9e69d0312533fda12297f2

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:fcef0025c0294f99eeb0e3bd64186f285801e4ea6f9e69d0312533fda12297f2

yaml
schemaVersion: "3"
displayName: Gitea
description: Wires a Gitea access token into the sandbox proxy so git-over-HTTPS and the Gitea API both authenticate against your instance, self-hosted or gitea.com. The token stays on the host.
version: 0.15.1
licenses:
    - MIT
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - ${{ kit.args.host }}
    - type: com.docker.sandbox/credential@1
      config:
        apiKey:
            inject:
                - domain: ${{ kit.args.host }}
                  format: token %s
                  header: Authorization
            name: GITEA_TOKEN
            proxyManaged: true
        phase: runtime
        service: gitea
      description: Gitea access token with the `write:repository` scope (add `write:issue` for issue/PR work). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to the instance.
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: |
                set -euo pipefail
                if [ -z "${GITEA_TOKEN:-}" ]; then
                  echo "GITEA_TOKEN unset (mode=${SBX_CRED_GITEA_MODE:-none}); skipping tea login" >&2
                  exit 0
                fi
                mkdir -p /home/agent/.config/tea
                cfg=/home/agent/.config/tea/config.yml
                : > "$cfg"
                chmod 0600 "$cfg"
                printf 'logins:\n' >> "$cfg"
                printf '  - name: sbx\n' >> "$cfg"
                printf '    url: https://%s\n' '${{ kit.args.host }}' >> "$cfg"
                printf '    token: %s\n' "$GITEA_TOKEN" >> "$cfg"
                printf '    default: true\n' >> "$cfg"
                printf '    ssh_host: ""\n' >> "$cfg"
                printf '    ssh_key: ""\n' >> "$cfg"
                printf '    insecure: false\n' >> "$cfg"
                printf '    ssh_agent: false\n' >> "$cfg"
                # No self-update check: unrelated egress, and the version is whatever
                # this kit pinned above.
                printf '    version_check: false\n' >> "$cfg"
                printf '    user: ""\n' >> "$cfg"
                printf '    created: 0\n' >> "$cfg"
              description: Point tea at the instance, authenticated with the proxy-managed sentinel
              env:
                - GITEA_TOKEN
                - SBX_CRED_GITEA_MODE
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        content: |
            ## Gitea

            This sandbox is wired to the Gitea instance at `${{ kit.args.host }}`.

            `GITEA_TOKEN` holds a sentinel value, not the real token: the sandbox proxy
            swaps it for the real one on requests to that host, and nowhere else. Do
            not read, print, or reconfigure it, and do not put it in a remote URL.

            **Git over HTTPS works directly.** Clone, pull, and push with plain HTTPS
            remotes -- no SSH key, no credential helper, no token in the URL:

                git clone https://${{ kit.args.host }}/<owner>/<repo>.git
                git push origin <branch>

            The proxy adds the `Authorization` header on the way out, including on
            git's first unauthenticated request, so private repositories work the same
            as public ones.

            **The REST API needs no auth header from you.** Send the request without
            one and the proxy fills it in:

                curl -s https://${{ kit.args.host }}/api/v1/user
                curl -s https://${{ kit.args.host }}/api/v1/repos/<owner>/<repo>/pulls

            Setting your own `Authorization` header is harmless -- the proxy replaces
            it -- but it is never necessary.

            **`tea`, Gitea's CLI, is installed and already logged in** against this
            host. Use it for the things it models well -- `tea pr`, `tea issue`,
            `tea repo`, `tea login ls` -- and `tea api` or `curl` for anything it does
            not cover. Its stored token is the same sentinel; do not try to "fix" it.
args:
    host:
        default: gitea.com
        description: Hostname of the Gitea instance, without a scheme or path (for example git.example.com). Defaults to gitea.com, Gitea's own hosted instance.
        pattern: ^[A-Za-z0-9]([A-Za-z0-9.-]*[A-Za-z0-9])?(:[0-9]{1,5})?$
    version:
        default: 0.15.1
        description: tea release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: TEA_VERSION