Document pulling the pre-built image from Gitea's container registry
Gitea's web UI uses Authelia/OIDC, but docker login needs a plain Gitea access token since the registry can't do a browser SSO redirect.
This commit is contained in:
@@ -35,6 +35,9 @@ local state, no task queue — a background thread handles the daily job.
|
|||||||
docker compose up -d --build
|
docker compose up -d --build
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Or, to use the pre-built image from Gitea's container registry instead of
|
||||||
|
building locally, see "Pulling the pre-built image" below.
|
||||||
|
|
||||||
4. Add a proxy host in NPMplus pointing at `boarding-pass:8080`, behind
|
4. Add a proxy host in NPMplus pointing at `boarding-pass:8080`, behind
|
||||||
Authelia, **except** for the two paths below (see "Approve/Deny callback
|
Authelia, **except** for the two paths below (see "Approve/Deny callback
|
||||||
paths").
|
paths").
|
||||||
@@ -72,6 +75,35 @@ token on every page load rather than relying on the surrounding page being
|
|||||||
behind Authelia. Don't add a `?token=` bypass anywhere else, and don't widen
|
behind Authelia. Don't add a `?token=` bypass anywhere else, and don't widen
|
||||||
the nginx match beyond these two paths.
|
the nginx match beyond these two paths.
|
||||||
|
|
||||||
|
## Pulling the pre-built image
|
||||||
|
|
||||||
|
Images are pushed to Gitea's container registry at
|
||||||
|
`gitea.apointless.space/bsncubed/boarding-pass`. To pull instead of building
|
||||||
|
locally:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker login gitea.apointless.space -u bsncubed
|
||||||
|
docker pull gitea.apointless.space/bsncubed/boarding-pass:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
Gitea's web login goes through Authelia (OIDC), but that's a browser SSO
|
||||||
|
flow that `docker login` can't do — the registry still authenticates with a
|
||||||
|
plain Gitea **personal access token**, not your Authelia/account password.
|
||||||
|
Generate one under Gitea → Settings → Applications with `read:package` scope
|
||||||
|
(`write:package` too if you'll also be pushing) and use it as the password.
|
||||||
|
|
||||||
|
Then point `docker-compose.yml` at the image instead of building:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
services:
|
||||||
|
boarding-pass:
|
||||||
|
image: gitea.apointless.space/bsncubed/boarding-pass:latest
|
||||||
|
# remove/comment out "build: ." above
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
|
and pull new versions with `docker compose pull && docker compose up -d`.
|
||||||
|
|
||||||
## Re-running the reference data build
|
## Re-running the reference data build
|
||||||
|
|
||||||
`data/airports.csv` and `data/airlines.csv` are trimmed snapshots of
|
`data/airports.csv` and `data/airlines.csv` are trimmed snapshots of
|
||||||
|
|||||||
Reference in New Issue
Block a user