Protected whatever --keep says: the controller floor, the vouched golden, the vouched agent and min_agent (the hub's
Configuration page), every image of ours the vouched golden baked (its bake.log), the hub manifest's image. The dry-run
prints each kept version and why. tests/test-prune-plan.sh pins it without network (red-proofed). No --apply was run.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
--all meant "all *container* packages": every API path hardcoded
type=container. admin/felhom-golden (type generic) was therefore
invisible to every mode of the script, and grew to 22 versions x
~627 MB = 13 GB — 88% of the gitea PVC — while
"--all --keep 7 --apply --reclaim" reported success against the
~1.3 GB of container images next to it.
--type defaults to container, so existing invocations are unchanged
(verified: felhom-hub still lists 9 tags with digest manifests and
a PROTECTED latest). Non-container types skip the OCI index ->
manifest -> blob indirection entirely and read sizes from the files
API, since their blobs are unique per version — which also means
apparent size IS the reclaimable size, so the shared-layer caveat
is replaced rather than repeated.
--all now warns that it covers one type only, and reclaim notes that
blobs newer than [cron.cleanup_packages] OLDER_THAN (24h) survive the
pass. Audit lines and the banner carry the type.
Sweeping both types needs two runs:
./gitea-image-prune.sh --all --keep 7 --apply --yes --reclaim
./gitea-image-prune.sh --type generic --all --keep 3 --apply --yes --reclaim
Also adds .gitignore for the logs/ directory the script writes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TzapW3g7zGnmjRrSLfqFQv
When GITEA_TOKEN/--token-file aren't set and the script runs inside a
Gitea-host clone, reuse git's stored credential: the token embedded in
the remote URL, else a configured credential helper (git credential fill,
no prompting). Switch to HTTP Basic auth (user:token) when a username is
known so both API tokens and the embedded-URL/helper credential work;
keep the token header for a bare GITEA_TOKEN. Banner reports the source.
Live-verified: env token + git credential helper (as kisfenyo) both list
and resolve OCI sizes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
New operator CLI (curl+jq, dry-run default) to list, prune (keep-N or
older-than), and reclaim old container images in the self-hosted Gitea
registry. Reclaim implements the three-step mechanism proven live on
Gitea 1.26.2: delete tag (frees only the index pointer) -> delete the
orphaned sha256 manifest versions (default cleanup_packages does NOT
remove untagged manifests) -> cleanup_packages cron GCs the now
unreferenced blobs. Orders by upload date, protects ^latest$, fail-closed
orphan detection, audit log, never logs the token.
Live-verified: single-version spike freed 5.1 MiB; cleaning felhom-hub's
16 orphan manifests freed 86 MiB; surviving tags still docker-pull.
felhom-controller and other packages left untouched for the operator.
Adds README section (usage, minimal token scopes, reclaim caveat, native
cleanup-rule recommendation), CHANGELOG, REPORT, and .gitattributes (LF).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>