Skip to content

Commit 0023048

Browse files
committed
build-packages template: disable sign-macos-packages for nightly
Change templates/build-packages.yml.jinja line 38 from hardcoded `sign-macos-packages: true` to the same per-environment conditional that sign-windows-packages and the others already use: sign-macos-packages: <% if gh_environment == 'nightly' -%> false <%- else -%> ${{ inputs.sign-macos-packages }} <%- endif %> Nightly builds no longer submit macOS packages to Apple's notary service. Rationale: 1. Public salt-nightlies today has `sign-macos-packages: true` in the rendered nightly.yml but the MAC_SIGN_APP_SPEC_PWD / APPLE_TEAM_ID / APPLE_ACCT secrets are empty at runtime, so the notarize step already effectively no-ops there. Setting the flag to false makes the workflow file match the effective behaviour instead of silently hiding it behind empty secrets. 2. Salt-priv (private security fork) inherits the same generated nightly.yml via forward-merge. Its Apple secrets ARE populated, which means the notarize step actually calls Apple's API. Any time those creds go stale (as they did today -- 2023-era app- specific password) the entire macOS build path fails, and by extension the whole nightly pipeline. Turning off signing for nightlies decouples nightly stability from Apple creds rotation. 3. Full releases still sign+notarize -- release.yml has its own path with dedicated sign-* inputs, and the release-context branch of the jinja conditional uses ${{ inputs.sign-macos- packages }} so callers can (and do) opt in. Regenerated .github/workflows/nightly.yml and staging.yml via the Generate GitHub Workflow Templates pre-commit hook. * nightly.yml: sign-macos-packages: true -> false (2 call sites) * staging.yml: sign-macos-packages: true -> ${{ inputs.sign-macos- packages }} (non-nightly branch; staging inputs preserve the prior configurability)
1 parent 7bb5938 commit 0023048

3 files changed

Lines changed: 5 additions & 5 deletions

File tree

‎.github/workflows/nightly.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -482,7 +482,7 @@ jobs:
482482
matrix: ${{ toJSON(fromJSON(needs.prepare-workflow.outputs.config)['build-matrix']) }}
483483
linux_arm_runner: ${{ fromJSON(needs.prepare-workflow.outputs.config)['linux_arm_runner'] }}
484484
environment: nightly
485-
sign-macos-packages: true
485+
sign-macos-packages: false
486486
sign-rpm-packages: true
487487
sign-deb-packages: true
488488
sign-windows-packages: false
@@ -505,7 +505,7 @@ jobs:
505505
matrix: ${{ toJSON(fromJSON(needs.prepare-workflow.outputs.config)['build-matrix']) }}
506506
linux_arm_runner: ${{ fromJSON(needs.prepare-workflow.outputs.config)['linux_arm_runner'] }}
507507
environment: nightly
508-
sign-macos-packages: true
508+
sign-macos-packages: false
509509
sign-rpm-packages: true
510510
sign-deb-packages: true
511511
sign-windows-packages: false

‎.github/workflows/staging.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -515,7 +515,7 @@ jobs:
515515
matrix: ${{ toJSON(fromJSON(needs.prepare-workflow.outputs.config)['build-matrix']) }}
516516
linux_arm_runner: ${{ fromJSON(needs.prepare-workflow.outputs.config)['linux_arm_runner'] }}
517517
environment: staging
518-
sign-macos-packages: true
518+
sign-macos-packages: ${{ inputs.sign-macos-packages }}
519519
sign-rpm-packages: ${{ inputs.sign-rpm-packages }}
520520
sign-deb-packages: ${{ inputs.sign-deb-packages }}
521521
sign-windows-packages: ${{ inputs.sign-windows-packages }}
@@ -538,7 +538,7 @@ jobs:
538538
matrix: ${{ toJSON(fromJSON(needs.prepare-workflow.outputs.config)['build-matrix']) }}
539539
linux_arm_runner: ${{ fromJSON(needs.prepare-workflow.outputs.config)['linux_arm_runner'] }}
540540
environment: staging
541-
sign-macos-packages: true
541+
sign-macos-packages: ${{ inputs.sign-macos-packages }}
542542
sign-rpm-packages: ${{ inputs.sign-rpm-packages }}
543543
sign-deb-packages: ${{ inputs.sign-deb-packages }}
544544
sign-windows-packages: ${{ inputs.sign-windows-packages }}

‎.github/workflows/templates/build-packages.yml.jinja‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
linux_arm_runner: ${{ fromJSON(needs.prepare-workflow.outputs.config)['linux_arm_runner'] }}
3636
<%- if gh_environment != "ci" %>
3737
environment: <{ gh_environment }>
38-
sign-macos-packages: true
38+
sign-macos-packages: <% if gh_environment == 'nightly' -%> false <%- else -%> ${{ inputs.sign-macos-packages }} <%- endif %>
3939
sign-rpm-packages: <% if gh_environment == 'nightly' -%> true <%- else -%> ${{ inputs.sign-rpm-packages }} <%- endif %>
4040
sign-deb-packages: <% if gh_environment == 'nightly' -%> true <%- else -%> ${{ inputs.sign-deb-packages }} <%- endif %>
4141
sign-windows-packages: <% if gh_environment == 'nightly' -%> false <%- else -%> ${{ inputs.sign-windows-packages }} <%- endif %>

0 commit comments

Comments
 (0)