Files
Oleg LukasonokandClaude Opus 4.8 8f46c3faa5 feat: devsecops-ci-cd-gitea skill — Gitea Actions → Harbor pipelines
Generate and maintain Gitea Actions CI/CD pipelines that build & publish
Docker images (applications-backend/*, applications-frontend/*) and OCI Helm
charts (helm-charts/*) from a pnpm + Turborepo monorepo to a Harbor registry,
authenticated by a project robot account via Gitea org secret + global vars.

- SKILL.md: auth model, convention-driven discovery, publish gating, gotchas
- references/harbor-auth.md: docker/helm login, robot accounts, secret/var
  taxonomy, bake-into-runner alternative, troubleshooting
- references/pipeline-workflow.md: jobs, discovery loops, tagging, turbo prune
- references/conventions.md: Dockerfile/chart locations, image & chart naming
- assets/workflows/ci-cd.yaml: ready-to-drop .gitea/workflows pipeline

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-13 00:10:03 +03:00

2.7 KiB

devsecops-ci-cd-gitea

Agent Skill for Gitea Actions CI/CD pipelines that build and publish the artifacts of a pnpm + Turborepo monorepo to a Harbor registry:

applications-backend/<svc>/Dockerfile   ─▶  image  harbor/<project>/<svc>:<tag>
applications-frontend/<app>/Dockerfile  ─▶  image  harbor/<project>/<app>:<tag>
helm-charts/<chart>/Chart.yaml          ─▶  OCI chart  harbor/<project>/charts/<chart>:<ver>

Discovery is convention-driven — the pipeline finds every app with a Dockerfile and every chart under helm-charts/, builds them, and pushes only on the default branch or a tag. Authentication uses a Harbor robot account whose credential lives in Gitea Actions secrets/variables — never a person's login, never a value committed to the repo.

The skill owns the pipeline up to "published to Harbor". Deploying the artifact is the development-gitops-argo-cd skill's job.

Layout

devsecops-ci-cd-gitea/
├── SKILL.md                          # Entry point — auth model, discovery, gating, gotchas
├── references/
│   ├── harbor-auth.md                # docker/helm login, robot accounts, Gitea vars/secrets, runner-bake
│   ├── pipeline-workflow.md          # jobs, discovery loops, tagging, gating, turbo prune
│   └── conventions.md                # where Dockerfiles/charts live, image & chart naming
└── assets/
    └── workflows/
        └── ci-cd.yaml                # ready-to-drop <repo>/.gitea/workflows/ci-cd.yaml

The one thing to get right up front

Build context is the repository root, always: docker build -f applications-backend/<svc>/Dockerfile … . — the Dockerfile runs turbo prune over the whole monorepo, so building from the app directory fails. And charts are centralized under helm-charts/, not co-located under the app — discover images and charts independently, with no assumed 1:1 mapping.

Registry auth in one table

Kind Name Scope Example
Variable HL_V1_HARBOR_ADDRESS global harbor-v1.apps.lego-cloud.eu
Variable HL_V1_HARBOR_ROBOT_GITEA_ACTIONS_V1_USERNAME global robot$gondor-v1+gitea-actions-v1
Secret HL_V1_HARBOR_ROBOT_GITEA_ACTIONS_V1_SECRET org (robot secret)

Username and address are not secret → global variables (set once). Gitea has no global-secret level, so the robot secret is a per-org secret. Details in references/harbor-auth.md.

Deploy

cd ../skill-manager/scripts
task deploy -- --skill-dir="$(cd ../../devsecops-ci-cd-gitea && pwd)"

Built with the skill-manager skill, following the agentskills.io specification.