Skip to content

Commit ceb2107

Browse files
committed
build-packages: rename SIGNING_GPG_KEY -> NIGHTLY_SIGNING_GPG_KEY
Rename the two secrets that build-packages.yml pulls for RPM/DEB signing: SIGNING_GPG_KEY -> NIGHTLY_SIGNING_GPG_KEY SIGNING_PASSPHRASE -> NIGHTLY_SIGNING_PASSPHRASE build-packages.yml is a reusable workflow called only from nightly.yml (release.yml has its own inline signing path that also references SIGNING_GPG_KEY -- unchanged by this PR). So this rename separates NIGHTLY signing key material from RELEASE signing key material at the secret-name level: * nightly signing: NIGHTLY_SIGNING_GPG_KEY / _PASSPHRASE * release signing: SIGNING_GPG_KEY / SIGNING_PASSPHRASE (unchanged) Motivation. Once a repo (public salt-nightlies, private salt-priv) does both nightly builds and formal releases, we don't want a single pair of secrets covering both. Different threat models, different rotation cadences, and in the private security flow potentially different keys entirely -- security nightlies should not be signed with the same key that signs public release artifacts. The step-local env variable inside the shell (`SIGNING_GPG_KEY`, `SIGNING_PASSPHRASE`) is intentionally left as-is -- those are internal to the step and the downstream `gpg --import` invocation doesn't care what the env var is named. Only the `secrets.<NAME>` reference at the env-block level is renamed. Post-merge action required on every repo that already runs nightly.yml (saltstack/salt-nightlies, saltstack/salt-priv, plus any dev fork that runs nightlies): gh secret set NIGHTLY_SIGNING_GPG_KEY --repo <repo> < privkey.asc gh secret set NIGHTLY_SIGNING_PASSPHRASE --repo <repo> --body '<passphrase>' The existing SIGNING_GPG_KEY / SIGNING_PASSPHRASE secrets on those repos remain in place and continue to sign release artifacts via release.yml. If a repo doesn't run releases (e.g. salt-priv today), leaving them unset is fine -- release.yml never fires there. Comment / description strings that mentioned SIGNING_GPG_KEY as a user-facing hint also updated to reflect the new name.
1 parent 97d9f00 commit ceb2107

1 file changed

Lines changed: 6 additions & 6 deletions

File tree

‎.github/workflows/build-packages.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ on:
2727
sign-deb-packages:
2828
type: boolean
2929
default: false
30-
description: Sign DEB Packages (via debsigs, using SIGNING_GPG_KEY)
30+
description: Sign DEB Packages (via debsigs, using NIGHTLY_SIGNING_GPG_KEY)
3131
sign-macos-packages:
3232
type: boolean
3333
default: false
@@ -167,8 +167,8 @@ jobs:
167167
- name: Setup GnuPG
168168
if: ${{ inputs.sign-deb-packages }}
169169
env:
170-
SIGNING_GPG_KEY: ${{ secrets.SIGNING_GPG_KEY }}
171-
SIGNING_PASSPHRASE: ${{ secrets.SIGNING_PASSPHRASE }}
170+
SIGNING_GPG_KEY: ${{ secrets.NIGHTLY_SIGNING_GPG_KEY }}
171+
SIGNING_PASSPHRASE: ${{ secrets.NIGHTLY_SIGNING_PASSPHRASE }}
172172
run: |
173173
install -d -m 0700 -o "$(id -u)" -g "$(id -g)" /run/gpg
174174
GNUPGHOME="$(mktemp -d -p /run/gpg)"
@@ -299,8 +299,8 @@ jobs:
299299
- name: Setup GnuPG
300300
if: ${{ inputs.sign-rpm-packages }}
301301
env:
302-
SIGNING_GPG_KEY: ${{ secrets.SIGNING_GPG_KEY }}
303-
SIGNING_PASSPHRASE: ${{ secrets.SIGNING_PASSPHRASE }}
302+
SIGNING_GPG_KEY: ${{ secrets.NIGHTLY_SIGNING_GPG_KEY }}
303+
SIGNING_PASSPHRASE: ${{ secrets.NIGHTLY_SIGNING_PASSPHRASE }}
304304
run: |
305305
install -d -m 0700 -o "$(id -u)" -g "$(id -g)" /run/gpg
306306
GNUPGHOME="$(mktemp -d -p /run/gpg)"
@@ -317,7 +317,7 @@ jobs:
317317
# Discover the fingerprint of the just-imported signing key so
318318
# Build RPM can pass it to rpmsign without hardcoding a specific
319319
# key id. Lets each repo (saltstack/salt, saltstack/salt-nightlies)
320-
# provide its own key material via SIGNING_GPG_KEY and have the
320+
# provide its own key material via NIGHTLY_SIGNING_GPG_KEY and have the
321321
# workflow use whatever's in the resulting keyring.
322322
SIGN_KEY_ID=$(gpg --list-secret-keys --with-colons | awk -F: '$1=="fpr" {print $10; exit}')
323323
echo "SIGN_KEY_ID=${SIGN_KEY_ID}" >> "$GITHUB_ENV"

0 commit comments

Comments
 (0)