The workflow requires access to Datum Container Registry, it means the CI check will fail for external contributor working with their own fork.
I am not sure how we want to fix this, but it sounds unusual for a CI check that runs in a PR to push to a container registry. I understand it is probably to be able to get an easy preview of the website via docker image.
/cc @scotwells not sure who should work at it