From faff70ded3735fbfb290075934b64c99ca06f2fa Mon Sep 17 00:00:00 2001 From: Dmitry Ilyin <6576495+widgetii@users.noreply.github.com> Date: Thu, 24 Sep 2026 17:06:25 +0300 Subject: [PATCH 1/2] ci: skip Docker publish (green) when DockerHub secrets are absent Enabling Actions made main.yml run on master, where it failed at 'Login to DockerHub' because DOCKERHUB_USERNAME/DOCKERHUB_TOKEN are not configured in this repo -- turning master red on every push. Gate the publish steps on the credentials being present: when unset, the job prints a notice and succeeds without publishing; when set, it logs in and pushes as before. Also correct the now-stale main.yml description in CLAUDE.md (it is master-only since it was scoped). --- .github/workflows/main.yml | 72 ++++++++++++++++++++++++-------------- CLAUDE.md | 7 ++-- 2 files changed, 50 insertions(+), 29 deletions(-) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 219295a..01153f9 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -1,27 +1,45 @@ -name: ci -on: - push: - branches: - - master - workflow_dispatch: -jobs: - docker: - runs-on: ubuntu-latest - # Publish only from master, even for manual workflow_dispatch runs, so a - # dispatch from a feature branch can't overwrite the :latest image. - if: github.ref == 'refs/heads/master' - steps: - - name: Set up QEMU - uses: docker/setup-qemu-action@v1 - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v1 - - name: Login to DockerHub - uses: docker/login-action@v1 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - - name: Build and push - uses: docker/build-push-action@v2 - with: - push: true - tags: braunbearded/python-dvr:latest,braunbearded/python-dvr:${{ github.sha }} +name: ci +on: + push: + branches: + - master + workflow_dispatch: +jobs: + docker: + runs-on: ubuntu-latest + # Publish only from master, even for manual workflow_dispatch runs, so a + # dispatch from a feature branch can't overwrite the :latest image. + if: github.ref == 'refs/heads/master' + env: + DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} + DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} + steps: + # Without DockerHub credentials the publish can't run; skip it (and keep + # the job green) instead of failing every push to master. + - name: Check DockerHub credentials + id: creds + run: | + if [ -n "$DOCKERHUB_USERNAME" ] && [ -n "$DOCKERHUB_TOKEN" ]; then + echo "present=true" >> "$GITHUB_OUTPUT" + else + echo "present=false" >> "$GITHUB_OUTPUT" + echo "::notice::DOCKERHUB_USERNAME/DOCKERHUB_TOKEN are not set; skipping the image publish." + fi + - name: Set up QEMU + if: steps.creds.outputs.present == 'true' + uses: docker/setup-qemu-action@v1 + - name: Set up Docker Buildx + if: steps.creds.outputs.present == 'true' + uses: docker/setup-buildx-action@v1 + - name: Login to DockerHub + if: steps.creds.outputs.present == 'true' + uses: docker/login-action@v1 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + - name: Build and push + if: steps.creds.outputs.present == 'true' + uses: docker/build-push-action@v2 + with: + push: true + tags: braunbearded/python-dvr:latest,braunbearded/python-dvr:${{ github.sha }} diff --git a/CLAUDE.md b/CLAUDE.md index c72a11e..df6c2ec 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -47,8 +47,11 @@ own `requirements.txt` and is self-contained. ### Docker / CI `Dockerfile` runs `download-local-files.py`. `.github/workflows/main.yml` -builds and pushes that image to Docker Hub on every branch push; -`codeql.yml` runs CodeQL Python analysis on master. +builds and pushes that image to Docker Hub on pushes to `master` (only +when the `DOCKERHUB_USERNAME`/`DOCKERHUB_TOKEN` secrets are set — it skips +the publish otherwise); `codeql.yml` runs CodeQL Python analysis on +master. `.github/workflows/test.yml` lint/smoke-tests the library on +pushes and PRs. ## Architecture From a07d17965a093076856db73141b417d57a908c46 Mon Sep 17 00:00:00 2001 From: Dmitry Ilyin <6576495+widgetii@users.noreply.github.com> Date: Thu, 24 Sep 2026 17:08:37 +0300 Subject: [PATCH 2/2] ci: scope DockerHub secrets to the credential-check step Address review: the secrets were declared as job-level env, exposing them to the QEMU/Buildx/build-push actions too. Only the shell check reads them as env (the login action receives them via its inputs), so move the env onto that step alone. --- .github/workflows/main.yml | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 01153f9..eb3636b 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -10,14 +10,15 @@ jobs: # Publish only from master, even for manual workflow_dispatch runs, so a # dispatch from a feature branch can't overwrite the :latest image. if: github.ref == 'refs/heads/master' - env: - DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} - DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} steps: # Without DockerHub credentials the publish can't run; skip it (and keep - # the job green) instead of failing every push to master. + # the job green) instead of failing every push to master. The secrets are + # scoped to this step only (the login action takes them via its inputs). - name: Check DockerHub credentials id: creds + env: + DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} + DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} run: | if [ -n "$DOCKERHUB_USERNAME" ] && [ -n "$DOCKERHUB_TOKEN" ]; then echo "present=true" >> "$GITHUB_OUTPUT"