diff --git a/README.md b/README.md index 7c1d822..306db15 100644 --- a/README.md +++ b/README.md @@ -108,6 +108,38 @@ For Kubernetes deployment, see examples in [CONFIGURATION.md](CONFIGURATION.md#k The repo includes a Gitea Actions workflow (`.gitea/workflows/build_push.yml`) that builds a multi-arch Docker image, pushes it to the gitea registry, and deploys to Kubernetes using the manifests in [`kube/`](kube/). The deployment uses a NodePort service exposing port 30002 (the Matrix appservice endpoint) and a persistent volume for thread memory. +### Gitea Actions Pipeline Variables + +The workflow reads the following from the gitea repository's **Settings → Actions → Secrets** and **Variables**: + +**Secrets** (sensitive): + +| Secret | Purpose | +|---|---| +| `KUBEC_CONFIG_BUILDX_NEW` | Kubeconfig for the buildx k8s driver + deploy step | +| `REG_PASSWORD` | Password for the gitea container registry login | +| `DOCKER_PASSWORD` | Password for the `regcred` docker-registry secret | +| `TELEGRAM_BOT_TOKEN` | Steward's Telegram bot token | +| `OPENAI_API_KEY` | LLM API key (or `ollama` placeholder for Ollama Cloud) | +| `MATRIX_AS_TOKEN` | Matrix appservice token (authenticates to homeserver) | +| `MATRIX_HS_TOKEN` | Matrix homeserver token (authenticates incoming transactions) | + +**Variables** (non-sensitive): + +| Variable | Purpose | +|---|---| +| `DOCKER_SERVER` | Registry host, e.g. `git.aridgwayweb.com` | +| `DOCKER_USERNAME` | Registry username, e.g. `armistace` | +| `DOCKER_EMAIL` | Registry email | +| `TELEGRAM_ALLOWED_USER_IDS` | Comma-separated Telegram user IDs | +| `OPENAI_BASE_URL` | LLM base URL (e.g. `https://ollama.com/v1` for Ollama Cloud) | +| `OPENAI_MODEL` | LLM model name | +| `MATRIX_HOMESERVER_URL` | Homeserver client-server base URL, e.g. `http://matrix:8008` | +| `MATRIX_HOMESERVER_DOMAIN` | Homeserver server_name, e.g. `matrix.aridgwayweb.com` | +| `MATRIX_BOT_LOCALPART` | Bot localpart (default `steward`) | +| `MATRIX_ALLOWED_ROOM_IDS` | Comma-separated room allow-list (empty = all) | +| `MATRIX_ALLOWED_USER_IDS` | Comma-separated user MXID allow-list (empty = all) | + Production image: `ghcr.io/djw4/steward:latest` ## License