- tests/gitea/recipe_meta.py: gitea as install-time dep provider; sqlite3 overlay EXTRA_ENV, health path /api/healthz, relaxed access for CI use - tests/drone/recipe_meta.py: DEPS=["gitea"]; health /healthz; 600s timeout - tests/drone/install_steps.sh: wires GITEA_CLIENT_ID + GITEA_DOMAIN + client_secret Docker secret + DRONE_USER_CREATE before single drone deploy - tests/drone/functional/test_scm_configured.py: Playwright-free SCM test — follows /login redirect, asserts final URL is gitea dep's OAuth2 authorize endpoint with matching client_id (per Adversary pre-probe REVIEW-drone.md) - tests/drone/PARITY.md: backup structural-skip justified (no backupbot labels) - runner/harness/sso.py: setup_gitea_oauth() — creates gitea admin user via CLI + OAuth2 app via API, returns {admin_user, admin_password, client_id, client_secret} for install_steps.sh consumption - runner/run_recipe_ci.py: _enrich_deps_with_sso now handles gitea dep (calls setup_gitea_oauth; keycloak path unchanged) - tests/unit/test_gitea_dep.py: unit tests for gitea dep path — meta loading, SSO routing, SCM redirect assertion logic (parametrized) - machine-docs: STATUS/JOURNAL/BACKLOG-drone.md phase state files initialized Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>