Skip to content

Commit 2787782

Browse files
committed
Switch from repo secrets to vars
- cleanup
1 parent 4e97bd1 commit 2787782

File tree

2 files changed

+20
-28
lines changed

2 files changed

+20
-28
lines changed

.github/workflows/release-build-sign-upload.yml

+8-12
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
runs-on: ubuntu-latest
5353

5454
outputs:
55-
aws-s3-bucket: "v${{ steps.parse-semver.outputs.version-major }}-cf-cli-releases"
55+
aws-s3-bucket: "v${{ steps.parse-semver.outputs.version-major }}-cf-cli-releases"
5656

5757
version-build: ${{ steps.parse-semver.outputs.version-build }}
5858
version-major: ${{ steps.parse-semver.outputs.version-major }}
@@ -730,8 +730,8 @@ jobs:
730730
actions: read
731731
contents: read
732732
env:
733-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
734-
AWS_REGION: ${{ secrets.AWS_REGION }}
733+
AWS_ACCESS_KEY_ID: ${{ vars.AWS_ACCESS_KEY_ID }}
734+
AWS_REGION: ${{ vars.AWS_REGION }}
735735
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
736736
AWS_S3_BUCKET: ${{ needs.setup.outputs.aws-s3-bucket }}
737737
VERSION_BUILD: ${{ needs.setup.outputs.version-build }}
@@ -836,17 +836,13 @@ jobs:
836836

837837
- name: Setup aws to upload installers to CLAW S3 bucket
838838
uses: aws-actions/configure-aws-credentials@v4
839-
env:
840-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
841-
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
842-
AWS_S3_ROLE_ARN: ${{ secrets.AWS_S3_ROLE_ARN }}
843839
with:
844-
aws-access-key-id: ${{ env.AWS_ACCESS_KEY_ID }}
845-
aws-secret-access-key: ${{ env.AWS_SECRET_ACCESS_KEY }}
846-
aws-region: us-west-1
847-
role-to-assume: ${{ env.AWS_S3_ROLE_ARN }}
840+
aws-access-key-id: ${{ vars.AWS_ACCESS_KEY_ID }}
841+
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
842+
aws-region: ${{ vars.AWS_REGION }}
843+
role-to-assume: ${{ vars.AWS_S3_ROLE_ARN }}
848844
role-skip-session-tagging: true
849-
role-duration-seconds: 1200
845+
role-duration-seconds: 1200
850846

851847
- name: Upload installers to CLAW S3 bucket
852848
run: aws s3 sync upload "s3://v${VERSION_MAJOR}-cf-cli-releases/releases/v${VERSION_BUILD}/"

.github/workflows/release-update-repos.yml

+12-16
Original file line numberDiff line numberDiff line change
@@ -300,13 +300,13 @@ jobs:
300300
301301
- name: Update Debian Repository
302302
env:
303-
DEBIAN_FRONTEND: noninteractive
304-
SIGNING_KEY_GPG_ID: ${{ secrets.SIGNING_KEY_GPG_ID }}
305-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
306-
AWS_BUCKET_NAME: cf-cli-debian-repo
307-
AWS_DEFAULT_REGION: us-west-2
303+
DEBIAN_FRONTEND: noninteractive
304+
SIGNING_KEY_GPG_ID: ${{ secrets.SIGNING_KEY_GPG_ID }}
305+
AWS_ACCESS_KEY_ID: ${{ vars.AWS_ACCESS_KEY_ID }}
306+
AWS_BUCKET_NAME: cf-cli-debian-repo
307+
AWS_DEFAULT_REGION: us-west-2
308308
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
309-
AWS_S3_ROLE_ARN: ${{ secrets.AWS_S3_ROLE_ARN }}
309+
AWS_S3_ROLE_ARN: ${{ vars.AWS_S3_ROLE_ARN }}
310310
run: |
311311
export $(printf "AWS_ACCESS_KEY_ID=%s AWS_SECRET_ACCESS_KEY=%s AWS_SESSION_TOKEN=%s" $(aws sts assume-role --role-arn ${AWS_S3_ROLE_ARN} --role-session-name foobar --output text --query "Credentials.[AccessKeyId,SecretAccessKey,SessionToken]"))
312312
deb-s3 upload installers/*.deb \
@@ -371,7 +371,7 @@ jobs:
371371
# TODO: fix backup
372372
# - name: Download current RPM repodata
373373
# env:
374-
# AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
374+
# AWS_ACCESS_KEY_ID: ${{ vars.AWS_ACCESS_KEY_ID }}
375375
# AWS_DEFAULT_REGION: us-east-1
376376
# AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
377377
# uses: docker://amazon/aws-cli:latest
@@ -405,17 +405,13 @@ jobs:
405405
406406
- name: Setup aws to upload installers to CLAW S3 bucket
407407
uses: aws-actions/configure-aws-credentials@v4
408-
env:
409-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
410-
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
411-
AWS_S3_ROLE_ARN: ${{ secrets.AWS_S3_ROLE_ARN }}
412408
with:
413-
aws-access-key-id: ${{ env.AWS_ACCESS_KEY_ID }}
414-
aws-secret-access-key: ${{ env.AWS_SECRET_ACCESS_KEY }}
415-
aws-region: us-west-1
416-
role-to-assume: ${{ env.AWS_S3_ROLE_ARN }}
409+
aws-access-key-id: ${{ vars.AWS_ACCESS_KEY_ID }}
410+
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
411+
aws-region: ${{ vars.AWS_REGION }}
412+
role-to-assume: ${{ vars.AWS_S3_ROLE_ARN }}
417413
role-skip-session-tagging: true
418-
role-duration-seconds: 1200
414+
role-duration-seconds: 1200
419415

420416
- name: Download V8 RPMs
421417
run: aws s3 sync --exclude "*" --include "releases/*/*installer*.rpm" s3://v8-cf-cli-releases .

0 commit comments

Comments
 (0)