sha256:fcef0025c0294f99eeb0e3bd64186f285801e4ea6f9e69d0312533fda12297f2
Last pushed
8 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:fcef0025c0294f99eeb0e3bd64186f285801e4ea6f9e69d0312533fda12297f2
schemaVersion: "3"
displayName: Gitea
description: Wires a Gitea access token into the sandbox proxy so git-over-HTTPS and the Gitea API both authenticate against your instance, self-hosted or gitea.com. The token stays on the host.
version: 0.15.1
licenses:
- MIT
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- ${{ kit.args.host }}
- type: com.docker.sandbox/credential@1
config:
apiKey:
inject:
- domain: ${{ kit.args.host }}
format: token %s
header: Authorization
name: GITEA_TOKEN
proxyManaged: true
phase: runtime
service: gitea
description: Gitea access token with the `write:repository` scope (add `write:issue` for issue/PR work). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to the instance.
- type: com.docker.sandbox/lifecycle@1
config:
install:
- command: |
set -euo pipefail
if [ -z "${GITEA_TOKEN:-}" ]; then
echo "GITEA_TOKEN unset (mode=${SBX_CRED_GITEA_MODE:-none}); skipping tea login" >&2
exit 0
fi
mkdir -p /home/agent/.config/tea
cfg=/home/agent/.config/tea/config.yml
: > "$cfg"
chmod 0600 "$cfg"
printf 'logins:\n' >> "$cfg"
printf ' - name: sbx\n' >> "$cfg"
printf ' url: https://%s\n' '${{ kit.args.host }}' >> "$cfg"
printf ' token: %s\n' "$GITEA_TOKEN" >> "$cfg"
printf ' default: true\n' >> "$cfg"
printf ' ssh_host: ""\n' >> "$cfg"
printf ' ssh_key: ""\n' >> "$cfg"
printf ' insecure: false\n' >> "$cfg"
printf ' ssh_agent: false\n' >> "$cfg"
# No self-update check: unrelated egress, and the version is whatever
# this kit pinned above.
printf ' version_check: false\n' >> "$cfg"
printf ' user: ""\n' >> "$cfg"
printf ' created: 0\n' >> "$cfg"
description: Point tea at the instance, authenticated with the proxy-managed sentinel
env:
- GITEA_TOKEN
- SBX_CRED_GITEA_MODE
user: "1000"
- type: com.docker.sandbox/agent-context@1
config:
content: |
## Gitea
This sandbox is wired to the Gitea instance at `${{ kit.args.host }}`.
`GITEA_TOKEN` holds a sentinel value, not the real token: the sandbox proxy
swaps it for the real one on requests to that host, and nowhere else. Do
not read, print, or reconfigure it, and do not put it in a remote URL.
**Git over HTTPS works directly.** Clone, pull, and push with plain HTTPS
remotes -- no SSH key, no credential helper, no token in the URL:
git clone https://${{ kit.args.host }}/<owner>/<repo>.git
git push origin <branch>
The proxy adds the `Authorization` header on the way out, including on
git's first unauthenticated request, so private repositories work the same
as public ones.
**The REST API needs no auth header from you.** Send the request without
one and the proxy fills it in:
curl -s https://${{ kit.args.host }}/api/v1/user
curl -s https://${{ kit.args.host }}/api/v1/repos/<owner>/<repo>/pulls
Setting your own `Authorization` header is harmless -- the proxy replaces
it -- but it is never necessary.
**`tea`, Gitea's CLI, is installed and already logged in** against this
host. Use it for the things it models well -- `tea pr`, `tea issue`,
`tea repo`, `tea login ls` -- and `tea api` or `curl` for anything it does
not cover. Its stored token is the same sentinel; do not try to "fix" it.
args:
host:
default: gitea.com
description: Hostname of the Gitea instance, without a scheme or path (for example git.example.com). Defaults to gitea.com, Gitea's own hosted instance.
pattern: ^[A-Za-z0-9]([A-Za-z0-9.-]*[A-Za-z0-9])?(:[0-9]{1,5})?$
version:
default: 0.15.1
description: tea release to install
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: TEA_VERSION