Keep source access action outside workflow discovery
Some checks failed
Canary release / release (push) Failing after 53s
Some checks failed
Canary release / release (push) Failing after 53s
This commit is contained in:
parent
4ad0faf307
commit
6691036b72
4 changed files with 3 additions and 3 deletions
|
|
@ -35,7 +35,7 @@ jobs:
|
|||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Bootstrap pinned tools and source credentials
|
||||
uses: ./.forgejo/workflows/source-access
|
||||
uses: ./.forgejo/source-access
|
||||
with:
|
||||
source-key: ${{ secrets.TENSAMIN_SOURCE_SSH_KEY }}
|
||||
known-hosts: ${{ vars.TENSAMIN_SSH_KNOWN_HOSTS }}
|
||||
|
|
|
|||
|
|
@ -27,7 +27,7 @@ jobs:
|
|||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Bootstrap pinned tools and source credentials
|
||||
uses: ./.forgejo/workflows/source-access
|
||||
uses: ./.forgejo/source-access
|
||||
with:
|
||||
source-key: ${{ secrets.TENSAMIN_SOURCE_SSH_KEY }}
|
||||
known-hosts: ${{ vars.TENSAMIN_SSH_KNOWN_HOSTS }}
|
||||
|
|
|
|||
|
|
@ -1,49 +0,0 @@
|
|||
name: Pinned source access
|
||||
description: Bootstrap public pinned tools before preparing private Nix source access
|
||||
inputs:
|
||||
source-key:
|
||||
description: SSH key with read access to locked sources
|
||||
required: true
|
||||
known-hosts:
|
||||
description: Verified SSH host keys
|
||||
required: true
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
- name: Bootstrap tools from the public nixpkgs lock
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
# Nix interpolation must remain literal for the evaluator.
|
||||
# shellcheck disable=SC2016
|
||||
tools=$(nix build --impure --no-link --print-out-paths --expr '
|
||||
let
|
||||
lock = builtins.fromJSON (builtins.readFile ./flake.lock);
|
||||
source = builtins.fetchTree lock.nodes.${lock.nodes.root.inputs.nixpkgs}.locked;
|
||||
pkgs = import source { system = builtins.currentSystem; };
|
||||
in pkgs.buildEnv {
|
||||
name = "release-bootstrap";
|
||||
paths = with pkgs; [ git openssh python3 bash coreutils ];
|
||||
}')
|
||||
printf '%s/bin\n' "$tools" >> "$GITHUB_PATH"
|
||||
- name: Prepare SSH and checkout fetch credentials
|
||||
shell: bash
|
||||
env:
|
||||
SOURCE_KEY: ${{ inputs.source-key }}
|
||||
KNOWN_HOSTS: ${{ inputs.known-hosts }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
umask 077
|
||||
home="$RUNNER_TEMP/tensamin-source"
|
||||
mkdir -p "$home/.ssh"
|
||||
printf '%s\n' "$SOURCE_KEY" > "$home/.ssh/key"
|
||||
printf '%s\n' "$KNOWN_HOSTS" > "$home/.ssh/known_hosts"
|
||||
printf 'Host *\n IdentityFile "%s/.ssh/key"\n IdentitiesOnly yes\n StrictHostKeyChecking yes\n UserKnownHostsFile "%s/.ssh/known_hosts"\n BatchMode yes\n' "$home" "$home" > "$home/.ssh/config"
|
||||
# An agent also supports Nix versions using libgit2 instead of Git's SSH command.
|
||||
eval "$(ssh-agent -s)"
|
||||
ssh-add "$home/.ssh/key"
|
||||
# The askpass process reads the token when Git invokes it.
|
||||
# shellcheck disable=SC2016
|
||||
printf '#!/bin/sh\ncase "$1" in *Username*) printf "%%s\\n" token;; *) printf "%%s\\n" "$RELEASE_TOKEN";; esac\n' > "$home/askpass"
|
||||
chmod 700 "$home/askpass"
|
||||
printf 'HOME=%s\nGIT_SSH_COMMAND=ssh -F "%s/.ssh/config"\nGIT_ASKPASS=%s/askpass\nGIT_TERMINAL_PROMPT=0\nSSH_AUTH_SOCK=%s\nSSH_AGENT_PID=%s\n' "$home" "$home" "$home" "$SSH_AUTH_SOCK" "$SSH_AGENT_PID" >> "$GITHUB_ENV"
|
||||
|
|
@ -46,7 +46,7 @@ jobs:
|
|||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Bootstrap pinned tools and source credentials
|
||||
uses: ./.forgejo/workflows/source-access
|
||||
uses: ./.forgejo/source-access
|
||||
with:
|
||||
source-key: ${{ secrets.TENSAMIN_SOURCE_SSH_KEY }}
|
||||
known-hosts: ${{ vars.TENSAMIN_SSH_KNOWN_HOSTS }}
|
||||
|
|
|
|||
Loading…
Reference in a new issue