fix gitea backend: plain docker commands, internal HTTP registry
Root cause: docker/build-push-action pushes via HTTPS to the
FQDN registry, hitting the self-signed cert. Also, GitHub
Actions (setup-buildx, login-action, trivy-action) have
compatibility issues with Gitea's act_runner.
Fix: replace ALL GitHub Actions with plain docker CLI commands:
- docker login gitea:3000 (internal HTTP, no TLS)
- docker build -t ... -f Dockerfile context/
- docker push (each tag)
- trivy via docker run (no action resolution needed)
ci_registry = "gitea:3000" in [ci.gitea] for internal push.
Host Docker daemon configured with insecure-registries for gitea:3000.