diff --git a/.tangled/workflows/release-image.yml b/.tangled/workflows/release-image.yml index 6829c31..4bc7997 100644 --- a/.tangled/workflows/release-image.yml +++ b/.tangled/workflows/release-image.yml @@ -5,8 +5,8 @@ # ghcr.io mirror is optional: it runs only when its secrets are set, and never # fails a release on its own. # -# Repository secrets: -# ATCR_USER, ATCR_TOKEN atproto handle and an app password +# Repository secrets (settings → secrets; ATCR_USER is set below, in the open): +# ATCR_TOKEN an app password for the ATCR_USER account # GHCR_USER, GHCR_TOKEN optional mirror — GitHub user and a PAT with # write:packages. Unset, the mirror step skips. # @@ -28,6 +28,11 @@ image: nixos virtualisation: docker: true +# Visible to anyone reading the repo, so only non-secret values belong here. +# The handle is already half of the published image name. +environment: + ATCR_USER: "chadtmiller.com" + steps: - name: "Check registry credentials" command: | @@ -53,8 +58,10 @@ steps: if [ -z "$configured" ]; then echo "No registry credentials set, so this tag would publish nothing." - echo "Set ATCR_USER/ATCR_TOKEN (and optionally GHCR_USER/GHCR_TOKEN)" - echo "in repository settings." + echo + echo "Add ATCR_TOKEN in repository settings — an app password for" + echo "${ATCR_USER:-the ATCR_USER account}. Or set GHCR_USER/GHCR_TOKEN" + echo "to publish the mirror instead." exit 1 fi