Authenticate setup-php against the GitHub API #175

Merged
thatguygriff merged 1 commits from ci/github-token-for-setup-php into main 2026-08-20 16:56:39 +00:00
3 changed files with 143 additions and 0 deletions
+80
View File
@@ -0,0 +1,80 @@
name: GitHub API token from 1Password
description: >
Resolve the GitHub API token that setup-php authenticates with, via the
1Password Connect instance running inside whichever cluster picked up this
job. Mirrors thatguygriff/infra .gitea/actions/op-connect, which is not
reachable from this repository.
inputs:
connect-host:
description: 1Password Connect host
required: true
op-connect-token-eris:
description: 1Password Connect token for the eris cluster
required: true
op-connect-token-kallone:
description: 1Password Connect token for the kallone cluster
required: true
op-connect-token-nemesis:
description: 1Password Connect token for the nemesis cluster
required: true
outputs:
token:
description: GitHub API token, for the GITHUB_TOKEN env of a setup-php step
value: ${{ steps.load.outputs.GH_API_TOKEN }}
runs:
using: composite
steps:
# Connect is addressed at a cluster-local Service, so the token has to match
# the cluster the job landed on. A value with no match would configure no
# host at all and fail somewhere less obvious.
- name: Check RUNNER_CLUSTER is recognised
shell: bash
run: |
case "${RUNNER_CLUSTER:-}" in
eris|kallone|nemesis) echo "Runner cluster: $RUNNER_CLUSTER" ;;
"") echo "::error::RUNNER_CLUSTER is unset; no 1Password Connect token can be selected"; exit 1 ;;
*) echo "::error::RUNNER_CLUSTER='$RUNNER_CLUSTER' has no matching 1Password Connect token"; exit 1 ;;
esac
- name: Configure Connect (eris)
if: env.RUNNER_CLUSTER == 'eris'
uses: 1password/load-secrets-action/configure@v2
with:
connect-host: ${{ inputs.connect-host }}
connect-token: ${{ inputs.op-connect-token-eris }}
- name: Configure Connect (kallone)
if: env.RUNNER_CLUSTER == 'kallone'
uses: 1password/load-secrets-action/configure@v2
with:
connect-host: ${{ inputs.connect-host }}
connect-token: ${{ inputs.op-connect-token-kallone }}
- name: Configure Connect (nemesis)
if: env.RUNNER_CLUSTER == 'nemesis'
uses: 1password/load-secrets-action/configure@v2
with:
connect-host: ${{ inputs.connect-host }}
connect-token: ${{ inputs.op-connect-token-nemesis }}
# export-env stays false so the token surfaces as a step output rather than
# entering the job environment, where `composer install` would run third
# party package scripts alongside it.
- name: Load GitHub API token
id: load
uses: 1password/load-secrets-action@v2
with:
export-env: false
env:
GH_API_TOKEN: "op://Unsupervised/GitHub Personal Access Token for Gitea/token"
- name: Verify token loaded
shell: bash
env:
GH_API_TOKEN: ${{ steps.load.outputs.GH_API_TOKEN }}
run: |
test -n "$GH_API_TOKEN" || { echo "::error::GitHub API token is empty after loading from 1Password"; exit 1; }
echo "GitHub API token loaded"
+48
View File
@@ -14,11 +14,26 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
# setup-php resolves its tools through the GitHub API, which allows 60
# requests an hour per source address unauthenticated. A CI fan-out across
# the fleet exhausts that, and the step then retries for minutes before
# reporting only "Could not setup PHP".
- name: Load GitHub API token
id: gh-token
uses: ./.gitea/actions/op-github-token
with:
connect-host: ${{ vars.OP_CONNECT_HOST }}
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
- name: Setup PHP - name: Setup PHP
uses: shivammathur/setup-php@v2 uses: shivammathur/setup-php@v2
with: with:
php-version: '8.3' php-version: '8.3'
tools: composer:v2 tools: composer:v2
env:
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
- name: Cache Composer packages - name: Cache Composer packages
uses: actions/cache@v3 uses: actions/cache@v3
@@ -39,11 +54,22 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Load GitHub API token
id: gh-token
uses: ./.gitea/actions/op-github-token
with:
connect-host: ${{ vars.OP_CONNECT_HOST }}
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
- name: Setup PHP - name: Setup PHP
uses: shivammathur/setup-php@v2 uses: shivammathur/setup-php@v2
with: with:
php-version: '8.3' php-version: '8.3'
tools: composer:v2 tools: composer:v2
env:
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
- name: Cache Composer packages - name: Cache Composer packages
uses: actions/cache@v3 uses: actions/cache@v3
@@ -70,6 +96,15 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Load GitHub API token
id: gh-token
uses: ./.gitea/actions/op-github-token
with:
connect-host: ${{ vars.OP_CONNECT_HOST }}
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
- name: Setup PHP - name: Setup PHP
uses: shivammathur/setup-php@v2 uses: shivammathur/setup-php@v2
with: with:
@@ -77,6 +112,8 @@ jobs:
extensions: mbstring, intl extensions: mbstring, intl
coverage: none coverage: none
tools: composer:v2 tools: composer:v2
env:
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
- name: Cache Composer packages - name: Cache Composer packages
uses: actions/cache@v3 uses: actions/cache@v3
@@ -113,11 +150,22 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Load GitHub API token
id: gh-token
uses: ./.gitea/actions/op-github-token
with:
connect-host: ${{ vars.OP_CONNECT_HOST }}
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
- name: Setup PHP - name: Setup PHP
uses: shivammathur/setup-php@v2 uses: shivammathur/setup-php@v2
with: with:
php-version: '8.3' php-version: '8.3'
tools: composer:v2 tools: composer:v2
env:
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
- name: Build plugin zip - name: Build plugin zip
run: composer build run: composer build
+15
View File
@@ -18,11 +18,26 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
# setup-php resolves its tools through the GitHub API, which allows 60
# requests an hour per source address unauthenticated. A CI fan-out across
# the fleet exhausts that, and the step then retries for minutes before
# reporting only "Could not setup PHP".
- name: Load GitHub API token
id: gh-token
uses: ./.gitea/actions/op-github-token
with:
connect-host: ${{ vars.OP_CONNECT_HOST }}
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
- name: Setup PHP - name: Setup PHP
uses: shivammathur/setup-php@v2 uses: shivammathur/setup-php@v2
with: with:
php-version: '8.3' php-version: '8.3'
tools: composer:v2 tools: composer:v2
env:
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
# A tag that disagrees with the plugin header would make sites see a # A tag that disagrees with the plugin header would make sites see a
# phantom update forever (or never see a real one), so fail fast. # phantom update forever (or never see a real one), so fail fast.