Authenticate setup-php against the GitHub API #175
@@ -0,0 +1,80 @@
|
|||||||
|
name: GitHub API token from 1Password
|
||||||
|
description: >
|
||||||
|
Resolve the GitHub API token that setup-php authenticates with, via the
|
||||||
|
1Password Connect instance running inside whichever cluster picked up this
|
||||||
|
job. Mirrors thatguygriff/infra .gitea/actions/op-connect, which is not
|
||||||
|
reachable from this repository.
|
||||||
|
|
||||||
|
inputs:
|
||||||
|
connect-host:
|
||||||
|
description: 1Password Connect host
|
||||||
|
required: true
|
||||||
|
op-connect-token-eris:
|
||||||
|
description: 1Password Connect token for the eris cluster
|
||||||
|
required: true
|
||||||
|
op-connect-token-kallone:
|
||||||
|
description: 1Password Connect token for the kallone cluster
|
||||||
|
required: true
|
||||||
|
op-connect-token-nemesis:
|
||||||
|
description: 1Password Connect token for the nemesis cluster
|
||||||
|
required: true
|
||||||
|
|
||||||
|
outputs:
|
||||||
|
token:
|
||||||
|
description: GitHub API token, for the GITHUB_TOKEN env of a setup-php step
|
||||||
|
value: ${{ steps.load.outputs.GH_API_TOKEN }}
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
# Connect is addressed at a cluster-local Service, so the token has to match
|
||||||
|
# the cluster the job landed on. A value with no match would configure no
|
||||||
|
# host at all and fail somewhere less obvious.
|
||||||
|
- name: Check RUNNER_CLUSTER is recognised
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
case "${RUNNER_CLUSTER:-}" in
|
||||||
|
eris|kallone|nemesis) echo "Runner cluster: $RUNNER_CLUSTER" ;;
|
||||||
|
"") echo "::error::RUNNER_CLUSTER is unset; no 1Password Connect token can be selected"; exit 1 ;;
|
||||||
|
*) echo "::error::RUNNER_CLUSTER='$RUNNER_CLUSTER' has no matching 1Password Connect token"; exit 1 ;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
- name: Configure Connect (eris)
|
||||||
|
if: env.RUNNER_CLUSTER == 'eris'
|
||||||
|
uses: 1password/load-secrets-action/configure@v2
|
||||||
|
with:
|
||||||
|
connect-host: ${{ inputs.connect-host }}
|
||||||
|
connect-token: ${{ inputs.op-connect-token-eris }}
|
||||||
|
|
||||||
|
- name: Configure Connect (kallone)
|
||||||
|
if: env.RUNNER_CLUSTER == 'kallone'
|
||||||
|
uses: 1password/load-secrets-action/configure@v2
|
||||||
|
with:
|
||||||
|
connect-host: ${{ inputs.connect-host }}
|
||||||
|
connect-token: ${{ inputs.op-connect-token-kallone }}
|
||||||
|
|
||||||
|
- name: Configure Connect (nemesis)
|
||||||
|
if: env.RUNNER_CLUSTER == 'nemesis'
|
||||||
|
uses: 1password/load-secrets-action/configure@v2
|
||||||
|
with:
|
||||||
|
connect-host: ${{ inputs.connect-host }}
|
||||||
|
connect-token: ${{ inputs.op-connect-token-nemesis }}
|
||||||
|
|
||||||
|
# export-env stays false so the token surfaces as a step output rather than
|
||||||
|
# entering the job environment, where `composer install` would run third
|
||||||
|
# party package scripts alongside it.
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: load
|
||||||
|
uses: 1password/load-secrets-action@v2
|
||||||
|
with:
|
||||||
|
export-env: false
|
||||||
|
env:
|
||||||
|
GH_API_TOKEN: "op://Unsupervised/GitHub Personal Access Token for Gitea/token"
|
||||||
|
|
||||||
|
- name: Verify token loaded
|
||||||
|
shell: bash
|
||||||
|
env:
|
||||||
|
GH_API_TOKEN: ${{ steps.load.outputs.GH_API_TOKEN }}
|
||||||
|
run: |
|
||||||
|
test -n "$GH_API_TOKEN" || { echo "::error::GitHub API token is empty after loading from 1Password"; exit 1; }
|
||||||
|
echo "GitHub API token loaded"
|
||||||
@@ -14,11 +14,26 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
# setup-php resolves its tools through the GitHub API, which allows 60
|
||||||
|
# requests an hour per source address unauthenticated. A CI fan-out across
|
||||||
|
# the fleet exhausts that, and the step then retries for minutes before
|
||||||
|
# reporting only "Could not setup PHP".
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: gh-token
|
||||||
|
uses: ./.gitea/actions/op-github-token
|
||||||
|
with:
|
||||||
|
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||||
|
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||||
|
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||||
|
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -39,11 +54,22 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: gh-token
|
||||||
|
uses: ./.gitea/actions/op-github-token
|
||||||
|
with:
|
||||||
|
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||||
|
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||||
|
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||||
|
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -70,6 +96,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: gh-token
|
||||||
|
uses: ./.gitea/actions/op-github-token
|
||||||
|
with:
|
||||||
|
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||||
|
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||||
|
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||||
|
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
@@ -77,6 +112,8 @@ jobs:
|
|||||||
extensions: mbstring, intl
|
extensions: mbstring, intl
|
||||||
coverage: none
|
coverage: none
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||||
|
|
||||||
- name: Cache Composer packages
|
- name: Cache Composer packages
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v3
|
||||||
@@ -113,11 +150,22 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: gh-token
|
||||||
|
uses: ./.gitea/actions/op-github-token
|
||||||
|
with:
|
||||||
|
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||||
|
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||||
|
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||||
|
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||||
|
|
||||||
- name: Build plugin zip
|
- name: Build plugin zip
|
||||||
run: composer build
|
run: composer build
|
||||||
|
|||||||
@@ -18,11 +18,26 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
# setup-php resolves its tools through the GitHub API, which allows 60
|
||||||
|
# requests an hour per source address unauthenticated. A CI fan-out across
|
||||||
|
# the fleet exhausts that, and the step then retries for minutes before
|
||||||
|
# reporting only "Could not setup PHP".
|
||||||
|
- name: Load GitHub API token
|
||||||
|
id: gh-token
|
||||||
|
uses: ./.gitea/actions/op-github-token
|
||||||
|
with:
|
||||||
|
connect-host: ${{ vars.OP_CONNECT_HOST }}
|
||||||
|
op-connect-token-eris: ${{ secrets.OP_CONNECT_TOKEN_ERIS }}
|
||||||
|
op-connect-token-kallone: ${{ secrets.OP_CONNECT_TOKEN_KALLONE }}
|
||||||
|
op-connect-token-nemesis: ${{ secrets.OP_CONNECT_TOKEN_NEMESIS }}
|
||||||
|
|
||||||
- name: Setup PHP
|
- name: Setup PHP
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
with:
|
with:
|
||||||
php-version: '8.3'
|
php-version: '8.3'
|
||||||
tools: composer:v2
|
tools: composer:v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.gh-token.outputs.token }}
|
||||||
|
|
||||||
# A tag that disagrees with the plugin header would make sites see a
|
# A tag that disagrees with the plugin header would make sites see a
|
||||||
# phantom update forever (or never see a real one), so fail fast.
|
# phantom update forever (or never see a real one), so fail fast.
|
||||||
|
|||||||
Reference in New Issue
Block a user