# devsecops-ci-cd-gitea Agent Skill for **Gitea Actions** CI/CD pipelines that build and publish the artifacts of a **pnpm + Turborepo** monorepo to a **Harbor** registry: ```text applications-backend//Dockerfile ─▶ image harbor//: applications-frontend//Dockerfile ─▶ image harbor//: helm-charts//Chart.yaml ─▶ OCI chart harbor//charts/: ``` Discovery is convention-driven — the pipeline finds every app with a `Dockerfile` and every chart under `helm-charts/`, builds them, and pushes only on the default branch or a tag. Authentication uses a Harbor **robot account** whose credential lives in Gitea Actions secrets/variables — never a person's login, never a value committed to the repo. The skill owns the pipeline up to *"published to Harbor"*. Deploying the artifact is the **development-gitops-argo-cd** skill's job. ## Layout ```text devsecops-ci-cd-gitea/ ├── SKILL.md # Entry point — auth model, discovery, gating, gotchas ├── references/ │ ├── harbor-auth.md # docker/helm login, robot accounts, Gitea vars/secrets, runner-bake │ ├── pipeline-workflow.md # jobs, discovery loops, tagging, gating, turbo prune │ └── conventions.md # where Dockerfiles/charts live, image & chart naming └── assets/ └── workflows/ └── ci-cd.yaml # ready-to-drop /.gitea/workflows/ci-cd.yaml ``` ## The one thing to get right up front **Build context is the repository root**, always: `docker build -f applications-backend//Dockerfile … .` — the Dockerfile runs `turbo prune` over the whole monorepo, so building from the app directory fails. And charts are **centralized under `helm-charts/`**, not co-located under the app — discover images and charts independently, with no assumed 1:1 mapping. ## Registry auth in one table | Kind | Name | Scope | Example | |---|---|---|---| | Variable | `HL_V1_HARBOR_ADDRESS` | global | `harbor-v1.apps.lego-cloud.eu` | | Variable | `HL_V1_HARBOR_ROBOT_GITEA_ACTIONS_V1_USERNAME` | global | `robot$gondor-v1+gitea-actions-v1` | | Secret | `HL_V1_HARBOR_ROBOT_GITEA_ACTIONS_V1_SECRET` | org | *(robot secret)* | Username and address are not secret → global variables (set once). Gitea has no global-secret level, so the robot secret is a per-org secret. Details in `references/harbor-auth.md`. ## Deploy ```bash cd ../skill-manager/scripts task deploy -- --skill-dir="$(cd ../../devsecops-ci-cd-gitea && pwd)" ``` Built with the `skill-manager` skill, following the [agentskills.io specification](https://agentskills.io/specification).