The third port of the same two things. Gitea walks WORKFLOW_DIRS and stops
at the first directory that exists, so .gitea/workflows/ replaces
.github/workflows/ outright on a Gitea instance — which is the point, since
deploy.yml there is built on repository_dispatch and an environment: and
Gitea has neither.
Four differences shape the files:
- No environment:, so no scoped secret and no required reviewers. The file
does not write the key at all rather than claim a protection that Gitea
parses and ignores; what gates a deploy is write access to the repository.
- No repository_dispatch. External callers post to the workflow dispatch
API, which fills in the same form — and can return a run id, so unlike
repository_dispatch the caller may follow the deploy it asked for.
- runs-on takes a literal label only, so GitHub's vars.DEPLOY_RUNNER
expression becomes one documented line to edit.
- A job is itself a container with no Docker socket, so the secret scan runs
the pinned gitleaks binary instead of the upstream image.
Input validation carries over unchanged and matters more here: type: choice
constrains the dispatch form, not the API.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>