ADR Suggestion Management of Organization-Wide GitHub Secrets
#53
AndrewSazonov
started this conversation in
Ideas
Replies: 1 comment 2 replies
-
|
Should we modify the description here in this discussion, or do you want to create a separate document? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Currently, we have 16 organization-wide secrets configured for GitHub Actions in the EasyScience organization:
https://github.com/organizations/easyscience/settings/secrets/actions
Many of these secrets are either no longer used, duplicated, or possibly not needed anymore. Over time, this makes it harder to understand:
Suggestion
I suggest documenting all organization-wide secrets in a dedicated ADR, including:
I also suggest that new organization-wide secrets are added only after discussion and by updating this ADR. This should help us keep a clear and up-to-date overview of all secrets over time.
Current overview
As a first step, I created the table below and added two extra columns: Status and Description. I filled in the entries I am confident about.
Please feel free to add comments, corrections, or missing details, so I can update the table accordingly.
Open points
KEYLOCKER_are still needed, it would be helpful to add a clearer explanation of what they are used for and which workflows depend on them.WINDOWS_CERT_secrets.More generally, when we have a group of related secrets, I suggest documenting the purpose of the group as a whole, together with a short explanation of each individual secret.
Beta Was this translation helpful? Give feedback.
All reactions