Merge pull request 'Stop authenticating setup-php against the GitHub API' (#177) from ci/drop-github-token-from-setup-php into main
CI / Coding Standards (push) Successful in 3m7s
CI / PHPStan (push) Successful in 6m42s
CI / Tests (PHP 8.1) (push) Successful in 2m11s
CI / Tests (PHP 8.2) (push) Successful in 1m6s
CI / No Debug Code (push) Successful in 2s
CI / Tests (PHP 8.3) (push) Successful in 12m55s
CI / Build Plugin Zip (push) Successful in 2m45s
CI / Coding Standards (push) Successful in 3m7s
CI / PHPStan (push) Successful in 6m42s
CI / Tests (PHP 8.1) (push) Successful in 2m11s
CI / Tests (PHP 8.2) (push) Successful in 1m6s
CI / No Debug Code (push) Successful in 2s
CI / Tests (PHP 8.3) (push) Successful in 12m55s
CI / Build Plugin Zip (push) Successful in 2m45s
Reviewed-on: #177
This commit was merged in pull request #177.
This commit is contained in:
@@ -1,80 +0,0 @@
|
|||||||
name: GitHub API token from 1Password
|
|
||||||
description: >
|
|
||||||
Resolve the GitHub API token that setup-php authenticates with, via the
|
|
||||||
1Password Connect instance running inside whichever cluster picked up this
|
|
||||||
job. Mirrors thatguygriff/infra .gitea/actions/op-connect, which is not
|
|
||||||
reachable from this repository.
|
|
||||||
|
|
||||||
inputs:
|
|
||||||
connect-host:
|
|
||||||
description: 1Password Connect host
|
|
||||||
required: true
|
|
||||||
op-connect-token-eris:
|
|
||||||
description: 1Password Connect token for the eris cluster
|
|
||||||
required: true
|
|
||||||
op-connect-token-kallone:
|
|
||||||
description: 1Password Connect token for the kallone cluster
|
|
||||||
required: true
|
|
||||||
op-connect-token-nemesis:
|
|
||||||
description: 1Password Connect token for the nemesis cluster
|
|
||||||
required: true
|
|
||||||
|
|
||||||
outputs:
|
|
||||||
token:
|
|
||||||
description: GitHub API token, for the GITHUB_TOKEN env of a setup-php step
|
|
||||||
value: ${{ steps.load.outputs.GH_API_TOKEN }}
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: composite
|
|
||||||
steps:
|
|
||||||
# Connect is addressed at a cluster-local Service, so the token has to match
|
|
||||||
# the cluster the job landed on. A value with no match would configure no
|
|
||||||
# host at all and fail somewhere less obvious.
|
|
||||||
- name: Check RUNNER_CLUSTER is recognised
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
case "${RUNNER_CLUSTER:-}" in
|
|
||||||
eris|kallone|nemesis) echo "Runner cluster: $RUNNER_CLUSTER" ;;
|
|
||||||
"") echo "::error::RUNNER_CLUSTER is unset; no 1Password Connect token can be selected"; exit 1 ;;
|
|
||||||
*) echo "::error::RUNNER_CLUSTER='$RUNNER_CLUSTER' has no matching 1Password Connect token"; exit 1 ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
- name: Configure Connect (eris)
|
|
||||||
if: env.RUNNER_CLUSTER == 'eris'
|
|
||||||
uses: 1password/load-secrets-action/configure@v2
|
|
||||||
with:
|
|
||||||
connect-host: ${{ inputs.connect-host }}
|
|
||||||
connect-token: ${{ inputs.op-connect-token-eris }}
|
|
||||||
|
|
||||||
- name: Configure Connect (kallone)
|
|
||||||
if: env.RUNNER_CLUSTER == 'kallone'
|
|
||||||
uses: 1password/load-secrets-action/configure@v2
|
|
||||||
with:
|
|
||||||
connect-host: ${{ inputs.connect-host }}
|
|
||||||
connect-token: ${{ inputs.op-connect-token-kallone }}
|
|
||||||
|
|
||||||
- name: Configure Connect (nemesis)
|
|
||||||
if: env.RUNNER_CLUSTER == 'nemesis'
|
|
||||||
uses: 1password/load-secrets-action/configure@v2
|
|
||||||
with:
|
|
||||||
connect-host: ${{ inputs.connect-host }}
|
|
||||||
connect-token: ${{ inputs.op-connect-token-nemesis }}
|
|
||||||
|
|
||||||
# export-env stays false so the token surfaces as a step output rather than
|
|
||||||
# entering the job environment, where `composer install` would run third
|
|
||||||
# party package scripts alongside it.
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: load
|
|
||||||
uses: 1password/load-secrets-action@v2
|
|
||||||
with:
|
|
||||||
export-env: false
|
|
||||||
env:
|
|
||||||
GH_API_TOKEN: "op://Unsupervised/GitHub Personal Access Token for Gitea/token"
|
|
||||||
|
|
||||||
- name: Verify token loaded
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
GH_API_TOKEN: ${{ steps.load.outputs.GH_API_TOKEN }}
|
|
||||||
run: |
|
|
||||||
test -n "$GH_API_TOKEN" || { echo "::error::GitHub API token is empty after loading from 1Password"; exit 1; }
|
|
||||||
echo "GitHub API token loaded"
|
|
||||||
@@ -14,26 +14,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
# setup-php resolves its tools through the GitHub API, which allows 60
|
|
||||||
# requests an hour per source address unauthenticated. A CI fan-out across
|
|
||||||
# the fleet exhausts that, and the step then retries for minutes before
|
|
||||||
# reporting only "Could not setup PHP".
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: gh-token
|
|
||||||
uses: ./.gitea/actions/op-github-token
|
|
||||||
with:
|
|
||||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
|
||||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
|
||||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
|
||||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -54,22 +39,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: gh-token
|
|
||||||
uses: ./.gitea/actions/op-github-token
|
|
||||||
with:
|
|
||||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
|
||||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
|
||||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
|
||||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -96,15 +70,6 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: gh-token
|
|
||||||
uses: ./.gitea/actions/op-github-token
|
|
||||||
with:
|
|
||||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
|
||||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
|
||||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
|
||||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
@@ -112,8 +77,6 @@ jobs:
|
|||||||
extensions: mbstring, intl
|
extensions: mbstring, intl
|
||||||
coverage: none
|
coverage: none
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -150,22 +113,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: gh-token
|
|
||||||
uses: ./.gitea/actions/op-github-token
|
|
||||||
with:
|
|
||||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
|
||||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
|
||||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
|
||||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
|
||||||
|
|
||||||
- name: Build plugin zip
|
- name: Build plugin zip
|
||||||
run: composer build
|
run: composer build
|
||||||
|
|||||||
@@ -18,26 +18,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
# setup-php resolves its tools through the GitHub API, which allows 60
|
|
||||||
# requests an hour per source address unauthenticated. A CI fan-out across
|
|
||||||
# the fleet exhausts that, and the step then retries for minutes before
|
|
||||||
# reporting only "Could not setup PHP".
|
|
||||||
- name: Load GitHub API token
|
|
||||||
id: gh-token
|
|
||||||
uses: ./.gitea/actions/op-github-token
|
|
||||||
with:
|
|
||||||
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
|
||||||
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
|
||||||
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
|
||||||
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
|
||||||
|
|
||||||
# A tag that disagrees with the plugin header would make sites see a
|
# A tag that disagrees with the plugin header would make sites see a
|
||||||
# phantom update forever (or never see a real one), so fail fast.
|
# phantom update forever (or never see a real one), so fail fast.
|
||||||
|
|||||||
Reference in New Issue
Block a user