fix(ci): derive IMAGE from github.repository, not the schedule-empty event payload

`${{ github.event.repository.name }}` resolves to EMPTY on `schedule`
events since the Gitea upgrade between 2026-07-01 and 2026-08-01, so
IMAGE became "justin/" and the monthly refresh died at the last step:

  ERROR: failed to build: invalid tag
  "192.168.0.2:1234/justin/:latest": invalid reference format

Both the 2026-08-01 and 2026-09-01 refreshes scraped, committed, pushed
and reindexed successfully, then failed to build the image — so the
corpus on main is current but the published container has been stale
since the 2026-07-01 run.

- IMAGE now comes from `${{ github.repository }}` (run context, not the
  event payload — `github.repository_owner` from the same source was
  resolving fine all along).
- The package-link and registry-GC steps take the bare repo name from
  `${GITHUB_REPOSITORY##*/}` (POSIX, safe under dash).
- New `Verify image name resolves` step fails in seconds instead of
  after a ~30 min scrape if this ever regresses.

Same fix applies to image-only.yml, which only escaped the bug because
push/workflow_dispatch events still carry the repository payload.

Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01FnVuG79cYPcRLTp4pC8ujR
This commit is contained in:
2026-09-01 11:10:32 -04:00
co-authored by Claude Opus 5
parent 215c7bb09a
commit 8b01847388
3 changed files with 37 additions and 7 deletions
+16 -3
View File
@@ -31,7 +31,7 @@ concurrency:
env: env:
REGISTRY_PUSH: 192.168.0.2:1234 REGISTRY_PUSH: 192.168.0.2:1234
REGISTRY_PULL: git.jpaul.io REGISTRY_PULL: git.jpaul.io
IMAGE: ${{ github.repository_owner }}/${{ github.event.repository.name }} IMAGE: ${{ github.repository }}
# 3-GPU LAN pool, weighted toward .0.125 (4090). See refresh.yml for # 3-GPU LAN pool, weighted toward .0.125 (4090). See refresh.yml for
# the bench numbers. .0.2:11434 excluded (not GPU-pinned). localhost # the bench numbers. .0.2:11434 excluded (not GPU-pinned). localhost
# excluded from CI (runner container has no Ollama on its loopback; # excluded from CI (runner container has no Ollama on its loopback;
@@ -51,6 +51,19 @@ jobs:
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Verify image name resolves
# ${{ github.event.repository.name }} silently resolves to EMPTY on
# schedule events (Gitea >=1.27), which built the tag
# "192.168.0.2:1234/justin/:latest" and failed the build only AFTER
# the full scrape. IMAGE now comes from github.repository; this step
# fails in seconds if it ever goes empty again.
run: |
echo "IMAGE=${IMAGE}"
case "${IMAGE}" in
*/?*) ;;
*) echo "ERROR: IMAGE did not resolve to owner/repo"; exit 1 ;;
esac
- name: Set up Python - name: Set up Python
uses: actions/setup-python@v5 uses: actions/setup-python@v5
with: with:
@@ -92,7 +105,7 @@ jobs:
GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: | run: |
OWNER="${{ github.repository_owner }}" OWNER="${{ github.repository_owner }}"
PKG="${{ github.event.repository.name }}" PKG="${GITHUB_REPOSITORY##*/}"
BODY=$(mktemp) BODY=$(mktemp)
CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \ CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \ -H "Authorization: token ${GITEA_TOKEN}" \
@@ -116,6 +129,6 @@ jobs:
run: | run: |
python scripts/registry_gc.py \ python scripts/registry_gc.py \
--owner "${{ github.repository_owner }}" \ --owner "${{ github.repository_owner }}" \
--package "${{ github.event.repository.name }}" \ --package "${GITHUB_REPOSITORY##*/}" \
--keep-days 180 \ --keep-days 180 \
--keep-latest 6 --keep-latest 6
+16 -3
View File
@@ -32,7 +32,7 @@ env:
# through the public hostname (response bodies aren't capped). # through the public hostname (response bodies aren't capped).
REGISTRY_PUSH: 192.168.0.2:1234 REGISTRY_PUSH: 192.168.0.2:1234
REGISTRY_PULL: git.jpaul.io REGISTRY_PULL: git.jpaul.io
IMAGE: ${{ github.repository_owner }}/${{ github.event.repository.name }} IMAGE: ${{ github.repository }}
# Embedder pool — 3 GPU-pinned endpoints reachable from the runner # Embedder pool — 3 GPU-pinned endpoints reachable from the runner
# container on .0.2. Measured throughput (50-chunk batches on # container on .0.2. Measured throughput (50-chunk batches on
@@ -63,6 +63,19 @@ jobs:
# produces a 0-byte history file. # produces a 0-byte history file.
fetch-depth: 0 fetch-depth: 0
- name: Verify image name resolves
# ${{ github.event.repository.name }} silently resolves to EMPTY on
# schedule events (Gitea >=1.27), which built the tag
# "192.168.0.2:1234/justin/:latest" and failed the build only AFTER
# the full scrape. IMAGE now comes from github.repository; this step
# fails in seconds if it ever goes empty again.
run: |
echo "IMAGE=${IMAGE}"
case "${IMAGE}" in
*/?*) ;;
*) echo "ERROR: IMAGE did not resolve to owner/repo"; exit 1 ;;
esac
- name: Set up Python - name: Set up Python
uses: actions/setup-python@v5 uses: actions/setup-python@v5
with: with:
@@ -176,7 +189,7 @@ jobs:
GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: | run: |
OWNER="${{ github.repository_owner }}" OWNER="${{ github.repository_owner }}"
PKG="${{ github.event.repository.name }}" PKG="${GITHUB_REPOSITORY##*/}"
BODY=$(mktemp) BODY=$(mktemp)
CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \ CODE=$(curl -sS -o "$BODY" -w "%{http_code}" -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \ -H "Authorization: token ${GITEA_TOKEN}" \
@@ -201,6 +214,6 @@ jobs:
run: | run: |
python scripts/registry_gc.py \ python scripts/registry_gc.py \
--owner "${{ github.repository_owner }}" \ --owner "${{ github.repository_owner }}" \
--package "${{ github.event.repository.name }}" \ --package "${GITHUB_REPOSITORY##*/}" \
--keep-days 180 \ --keep-days 180 \
--keep-latest 6 --keep-latest 6
+5 -1
View File
@@ -194,7 +194,11 @@ template's PLAN.md.
### Image name and package linking are repo-name-derived ### Image name and package linking are repo-name-derived
`IMAGE` and `--package` derive from the repo at runtime via `IMAGE` and `--package` derive from the repo at runtime via
`${{ github.repository_owner }}` / `${{ github.event.repository.name }}`. `${{ github.repository }}` / `${GITHUB_REPOSITORY##*/}`. Do **not** use
`${{ github.event.repository.name }}` — it resolves to EMPTY on
`schedule` events (Gitea >= 1.27), which silently builds the tag
`192.168.0.2:1234/<owner>/:latest` and fails the build *after* the
full scrape. The `Verify image name resolves` step guards it.
The only workflow placeholders customized per clone are The only workflow placeholders customized per clone are
`REGISTRY_PUSH=192.168.0.2:1234`, `REGISTRY_PULL=git.jpaul.io`, `REGISTRY_PUSH=192.168.0.2:1234`, `REGISTRY_PULL=git.jpaul.io`,
and the `OLLAMA_URL` embed pool. and the `OLLAMA_URL` embed pool.