Authenticate setup-php against the GitHub API
CI / PHPStan (pull_request) Successful in 6m52s
CI / Tests (PHP 8.1) (pull_request) Successful in 6m0s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m11s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m55s
CI / No Debug Code (pull_request) Successful in 2s
CI / Coding Standards (pull_request) Successful in 7m6s
CI / Build Plugin Zip (pull_request) Skipped
CI / PHPStan (pull_request) Successful in 6m52s
CI / Tests (PHP 8.1) (pull_request) Successful in 6m0s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m11s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m55s
CI / No Debug Code (pull_request) Successful in 2s
CI / Coding Standards (pull_request) Successful in 7m6s
CI / Build Plugin Zip (pull_request) Skipped
setup-php resolves its tools through the GitHub API, unauthenticated at 60 requests an hour per source address. A CI fan-out across the fleet exhausts that bucket, and the step then retries for several minutes before reporting only "Could not setup PHP 8.3". It reads as a hang rather than a throttle, and it took out both a main CI run and a release build. Each cluster has its own egress address and so its own bucket, which is why the same job passed on one runner and failed on another in the same minute. The token comes from 1Password through the Connect instance in whichever cluster picked up the job, matching the pattern in thatguygriff/infra. That repository's composite action is not reachable from here, so it is mirrored locally. It stays a step output rather than being exported to the job environment, to keep it away from the package scripts composer install runs. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_0133tYSQoZhoKebKZV8o2GPs
This commit is contained in:
@@ -14,11 +14,26 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# setup-php resolves its tools through the GitHub API, which allows 60
|
||||
# requests an hour per source address unauthenticated. A CI fan-out across
|
||||
# the fleet exhausts that, and the step then retries for minutes before
|
||||
# reporting only "Could not setup PHP".
|
||||
- name: Load GitHub API token
|
||||
id: gh-token
|
||||
uses: ./.gitea/actions/op-github-token
|
||||
with:
|
||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.3'
|
||||
tools: composer:v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||
|
||||
- name: Cache Composer packages
|
||||
uses: actions/cache@v3
|
||||
@@ -39,11 +54,22 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Load GitHub API token
|
||||
id: gh-token
|
||||
uses: ./.gitea/actions/op-github-token
|
||||
with:
|
||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.3'
|
||||
tools: composer:v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||
|
||||
- name: Cache Composer packages
|
||||
uses: actions/cache@v3
|
||||
@@ -70,6 +96,15 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Load GitHub API token
|
||||
id: gh-token
|
||||
uses: ./.gitea/actions/op-github-token
|
||||
with:
|
||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
@@ -77,6 +112,8 @@ jobs:
|
||||
extensions: mbstring, intl
|
||||
coverage: none
|
||||
tools: composer:v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||
|
||||
- name: Cache Composer packages
|
||||
uses: actions/cache@v3
|
||||
@@ -113,11 +150,22 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Load GitHub API token
|
||||
id: gh-token
|
||||
uses: ./.gitea/actions/op-github-token
|
||||
with:
|
||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.3'
|
||||
tools: composer:v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||
|
||||
- name: Build plugin zip
|
||||
run: composer build
|
||||
|
||||
@@ -18,11 +18,26 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# setup-php resolves its tools through the GitHub API, which allows 60
|
||||
# requests an hour per source address unauthenticated. A CI fan-out across
|
||||
# the fleet exhausts that, and the step then retries for minutes before
|
||||
# reporting only "Could not setup PHP".
|
||||
- name: Load GitHub API token
|
||||
id: gh-token
|
||||
uses: ./.gitea/actions/op-github-token
|
||||
with:
|
||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||
|
||||
- name: Setup PHP
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.3'
|
||||
tools: composer:v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||
|
||||
# A tag that disagrees with the plugin header would make sites see a
|
||||
# phantom update forever (or never see a real one), so fail fast.
|
||||
|
||||
Reference in New Issue
Block a user