Commit 0023048
committed
build-packages template: disable sign-macos-packages for nightly
Change templates/build-packages.yml.jinja line 38 from hardcoded
`sign-macos-packages: true` to the same per-environment conditional
that sign-windows-packages and the others already use:
sign-macos-packages: <% if gh_environment == 'nightly' -%> false
<%- else -%> ${{ inputs.sign-macos-packages }}
<%- endif %>
Nightly builds no longer submit macOS packages to Apple's notary
service. Rationale:
1. Public salt-nightlies today has `sign-macos-packages: true` in
the rendered nightly.yml but the MAC_SIGN_APP_SPEC_PWD /
APPLE_TEAM_ID / APPLE_ACCT secrets are empty at runtime, so the
notarize step already effectively no-ops there. Setting the
flag to false makes the workflow file match the effective
behaviour instead of silently hiding it behind empty secrets.
2. Salt-priv (private security fork) inherits the same generated
nightly.yml via forward-merge. Its Apple secrets ARE populated,
which means the notarize step actually calls Apple's API. Any
time those creds go stale (as they did today -- 2023-era app-
specific password) the entire macOS build path fails, and by
extension the whole nightly pipeline. Turning off signing for
nightlies decouples nightly stability from Apple creds rotation.
3. Full releases still sign+notarize -- release.yml has its own
path with dedicated sign-* inputs, and the release-context
branch of the jinja conditional uses ${{ inputs.sign-macos-
packages }} so callers can (and do) opt in.
Regenerated .github/workflows/nightly.yml and staging.yml via the
Generate GitHub Workflow Templates pre-commit hook.
* nightly.yml: sign-macos-packages: true -> false (2 call sites)
* staging.yml: sign-macos-packages: true -> ${{ inputs.sign-macos-
packages }} (non-nightly branch; staging inputs preserve the
prior configurability)1 parent 7bb5938 commit 0023048
3 files changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
482 | 482 | | |
483 | 483 | | |
484 | 484 | | |
485 | | - | |
| 485 | + | |
486 | 486 | | |
487 | 487 | | |
488 | 488 | | |
| |||
505 | 505 | | |
506 | 506 | | |
507 | 507 | | |
508 | | - | |
| 508 | + | |
509 | 509 | | |
510 | 510 | | |
511 | 511 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
515 | 515 | | |
516 | 516 | | |
517 | 517 | | |
518 | | - | |
| 518 | + | |
519 | 519 | | |
520 | 520 | | |
521 | 521 | | |
| |||
538 | 538 | | |
539 | 539 | | |
540 | 540 | | |
541 | | - | |
| 541 | + | |
542 | 542 | | |
543 | 543 | | |
544 | 544 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| |||
0 commit comments