Commit b86c45c8a5
Verified · cmc
Layout: unified · split
Admin.org +6
| @@ -201,6 +201,12 @@ v1 runs steps directly on the host — no containers — so treat the | |||
| 201 | runner machine as executing whatever your users push. Install the | 201 | runner machine as executing whatever your users push. Install the |
| 202 | toolchains your builds need on it. | 202 | toolchains your builds need on it. |
| 203 | 203 | ||
| 204 | Instance admin on the runner account only authorizes the claim/report | ||
| 205 | protocol; it grants no repo access. A build that pushes back — a pages | ||
| 206 | deploy, an archive publish, an automated MR branch — needs an explicit | ||
| 207 | grant on that repo: =repo access grant <owner/name> ci write=. Private | ||
| 208 | repos likewise need at least read for the clone. | ||
| 209 | |||
| 204 | * Pages | 210 | * Pages |
| 205 | 211 | ||
| 206 | =[pages] domain = "example.site"= serves public repos' =pages= branches | 212 | =[pages] domain = "example.site"= serves public repos' =pages= branches |