# gitea-actions Shared **public** Gitea Actions composite actions for the SpikerSoft org. Public on purpose: these contain only workflow *logic* (shell/curl/jq), never secrets. Runners can clone this repo anonymously, which is why shared actions live here instead of the private `spikersoft-infrastructure` repo (a private repo can't be cloned by a job token scoped to a different repo). ## Actions - **bao-secrets** — AppRole-login to OpenBao and export requested KV v2 secrets into the job env (masked). Phase 1, spikersoft-issues#545. ```yaml - uses: https://git.spikersoft.com/spikerj/gitea-actions/bao-secrets@master with: role-id: ${{ secrets.BAO_ROLE_ID }} secret-id: ${{ secrets.BAO_SECRET_ID }} secrets: | DOCKER_PASSWORD secret/ci/shared/registry password ``` Reference by full URL (`https://git.spikersoft.com/...`) so Gitea resolves it from this instance instead of github.com.