From bd85229e7105390d8cf2b0f9a0f98b2f2183365f Mon Sep 17 00:00:00 2001 From: ben Date: Sat, 4 Jul 2026 22:50:34 +1000 Subject: [PATCH] Document pulling the pre-built image from Gitea's container registry Gitea's web UI uses Authelia/OIDC, but docker login needs a plain Gitea access token since the registry can't do a browser SSO redirect. --- README.md | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/README.md b/README.md index 81c2446..a77d661 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,9 @@ local state, no task queue — a background thread handles the daily job. docker compose up -d --build ``` + Or, to use the pre-built image from Gitea's container registry instead of + building locally, see "Pulling the pre-built image" below. + 4. Add a proxy host in NPMplus pointing at `boarding-pass:8080`, behind Authelia, **except** for the two paths below (see "Approve/Deny callback paths"). @@ -72,6 +75,35 @@ token on every page load rather than relying on the surrounding page being behind Authelia. Don't add a `?token=` bypass anywhere else, and don't widen the nginx match beyond these two paths. +## Pulling the pre-built image + +Images are pushed to Gitea's container registry at +`gitea.apointless.space/bsncubed/boarding-pass`. To pull instead of building +locally: + +```bash +docker login gitea.apointless.space -u bsncubed +docker pull gitea.apointless.space/bsncubed/boarding-pass:latest +``` + +Gitea's web login goes through Authelia (OIDC), but that's a browser SSO +flow that `docker login` can't do — the registry still authenticates with a +plain Gitea **personal access token**, not your Authelia/account password. +Generate one under Gitea → Settings → Applications with `read:package` scope +(`write:package` too if you'll also be pushing) and use it as the password. + +Then point `docker-compose.yml` at the image instead of building: + +```yaml +services: + boarding-pass: + image: gitea.apointless.space/bsncubed/boarding-pass:latest + # remove/comment out "build: ." above + ... +``` + +and pull new versions with `docker compose pull && docker compose up -d`. + ## Re-running the reference data build `data/airports.csv` and `data/airlines.csv` are trimmed snapshots of