Skip to content

Commit e5d4dcd

Browse files
committed
Replace PAT with GitHub App generated token in release workflows
1 parent baaf604 commit e5d4dcd

File tree

3 files changed

+44
-7
lines changed

3 files changed

+44
-7
lines changed

.github/workflows/update-release-status.yml

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -134,11 +134,23 @@ jobs:
134134
135135
echo "check-run-head-sha=$CHECK_RUN_HEAD_SHA" >> "$GITHUB_OUTPUT"
136136
137+
generate-token:
138+
runs-on: ubuntu-latest
139+
outputs:
140+
token: ${{ steps.generate-token.outputs.token }}
141+
steps:
142+
- name: Generate token
143+
id: generate-token
144+
uses: actions/create-github-app-token@eaddb9eb7e4226c68cf4b39f167c83e5bd132b3e
145+
with:
146+
app_id: ${{ vars.AUTOMATION_APP_ID }}
147+
private_key: ${{ secrets.AUTOMATION_PRIVATE_KEY }}
148+
137149
update-release:
138-
needs: validate-check-runs
150+
needs: [validate-check-runs, generate-token]
139151
if: needs.validate-check-runs.outputs.status == 'completed'
140152
uses: ./.github/workflows/update-release.yml
141153
with:
142154
head-sha: ${{ needs.validate-check-runs.outputs.check-run-head-sha }}
143155
secrets:
144-
RELEASE_ENGINEERING_TOKEN: ${{ secrets.RELEASE_ENGINEERING_TOKEN }}
156+
RELEASE_ENGINEERING_TOKEN: ${{ generate-token.outputs.token }}

.github/workflows/update-release.yml

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,22 @@ env:
2323
HEAD_SHA: ${{ inputs.head-sha }}
2424

2525
jobs:
26+
27+
generate-token:
28+
runs-on: ubuntu-latest
29+
outputs:
30+
token: ${{ steps.generate-token.outputs.token }}
31+
steps:
32+
- name: Generate token
33+
id: generate-token
34+
uses: actions/create-github-app-token@eaddb9eb7e4226c68cf4b39f167c83e5bd132b3e
35+
with:
36+
app_id: ${{ vars.AUTOMATION_APP_ID }}
37+
private_key: ${{ secrets.AUTOMATION_PRIVATE_KEY }}
38+
2639
update-release:
2740
name: "Update release"
41+
needs: generate-token
2842
runs-on: ubuntu-22.04
2943
steps:
3044
- name: Checkout
@@ -43,7 +57,7 @@ jobs:
4357
- name: Update release assets
4458
env:
4559
GITHUB_TOKEN: ${{ github.token }}
46-
RELEASE_ENGINEERING_TOKEN: ${{ secrets.RELEASE_ENGINEERING_TOKEN }}
60+
RELEASE_ENGINEERING_TOKEN: ${{ generate-token.outputs.token }}
4761
run: |
4862
python scripts/release/update-release-assets.py \
4963
--head-sha $HEAD_SHA \

.github/workflows/validate-release.yml

Lines changed: 15 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,17 @@ env:
1414
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
1515

1616
jobs:
17+
generate-token:
18+
runs-on: ubuntu-latest
19+
outputs:
20+
token: ${{ steps.generate-token.outputs.token }}
21+
steps:
22+
- name: Generate token
23+
id: generate-token
24+
uses: actions/create-github-app-token@eaddb9eb7e4226c68cf4b39f167c83e5bd132b3e
25+
with:
26+
app_id: ${{ vars.AUTOMATION_APP_ID }}
27+
private_key: ${{ secrets.AUTOMATION_PRIVATE_KEY }}
1728

1829
pre-validate-performance:
1930
outputs:
@@ -36,13 +47,13 @@ jobs:
3647
echo "check-run-id=$check_run_id" >> "$GITHUB_OUTPUT"
3748
3849
validate-performance:
39-
needs: pre-validate-performance
50+
needs: [pre-validate-performance, generate-token]
4051
runs-on: ubuntu-22.04
4152
steps:
4253
- name: Invoke performance test
4354
env:
4455
CHECK_RUN_ID: ${{ needs.pre-validate-performance.outputs.check-run-id }}
45-
GH_TOKEN: ${{ secrets.RELEASE_ENGINEERING_TOKEN }}
56+
GH_TOKEN: ${{ generate-token.outputs.token }}
4657
run: |
4758
jq -n \
4859
--arg ref "$HEAD_SHA" \
@@ -97,13 +108,13 @@ jobs:
97108
echo "check-run-id=$check_run_id" >> "$GITHUB_OUTPUT"
98109
99110
validate-compiler-compatibility:
100-
needs: pre-validate-compiler-compatibility
111+
needs: [pre-validate-compiler-compatibility, generate-token]
101112
runs-on: ubuntu-22.04
102113
steps:
103114
- name: Invoke compiler compatibility test
104115
env:
105116
CHECK_RUN_ID: ${{ needs.pre-validate-compiler-compatibility.outputs.check-run-id }}
106-
GITHUB_TOKEN: ${{ secrets.RELEASE_ENGINEERING_TOKEN }}
117+
GITHUB_TOKEN: ${{ generate-token.outputs.token }}
107118
run: |
108119
jq -n \
109120
--arg ref "$HEAD_SHA" \

0 commit comments

Comments
 (0)