fix(ci): give the stable-release reusable workflows their environment secrets
stable-release.yml called desktop-bundled-release.yml, docker.yml and termux-verify.yml without `secrets: inherit`, so every job inside them that declares `environment: release-signing` (or container-publish) attached its deployment and read the environment's `vars`, but resolved `secrets.*` to the empty string. The signed-candidate legs died at "Archive every pinned input" with `missing env CLOUDFLARE_R2_ACCESS_KEY_ID`; the docker publish legs and the termux packaging checks would have failed the same way. A called workflow receives no secrets by default, and a job-level `environment:` inside it is required but not sufficient: a caller job that `uses:` a reusable workflow cannot declare `environment:` at all, so `secrets: inherit` is the only mechanism that can carry them (actions/runner#1490). `secrets: inherit` is added only where the callee reads a protected environment's secrets. ci.yaml, nix, pm-bundle, windows-venv-e2e and the install-e2e chain reference none, and ci.yaml must stay secret-free by its own header (it runs PR-controlled code).
This commit is contained in:
@@ -58,6 +58,11 @@ name: Desktop Bundled Release
|
||||
# Manual dispatch selects a tag or a pushed full commit. Commit dispatches
|
||||
# use the default-branch workflow and require maintainer permission.
|
||||
#
|
||||
# Callers must dispatch with `secrets: inherit`: a called workflow receives
|
||||
# no secrets by default, and a job-level `environment:` alone attaches the
|
||||
# deployment and exposes `vars` but NOT that environment's secrets
|
||||
# (actions/runner#1490).
|
||||
#
|
||||
# R2 secrets (repo-level or the release-signing environment): the R2
|
||||
# account id + an R2 API token (S3-compatible) with read/write on the
|
||||
# release bucket; CLOUDFLARE_R2_BUCKET and CLOUDFLARE_R2_PUBLIC_URL are
|
||||
|
||||
@@ -17,6 +17,13 @@ on:
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
# Every reusable workflow called below inherits secrets (`secrets: inherit`)
|
||||
# because their release-signing jobs need protected-environment secrets. A
|
||||
# called workflow only sees them when the caller inherits AND the called job
|
||||
# declares the environment: the job-level `environment:` alone attaches the
|
||||
# deployment and exposes `vars`, but leaves `secrets.*` empty
|
||||
# (actions/runner#1490). ci.yaml is deliberately excluded — it runs
|
||||
# PR-controlled code and must stay secret-free.
|
||||
concurrency:
|
||||
group: stable-release
|
||||
cancel-in-progress: false
|
||||
@@ -76,6 +83,7 @@ jobs:
|
||||
if: >-
|
||||
!cancelled() && needs.admit.result == 'success'
|
||||
uses: ./.github/workflows/docker.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
release-phase: test
|
||||
skip-tests: ${{ needs.admit.outputs.skip-tests == 'true' }}
|
||||
@@ -109,6 +117,7 @@ jobs:
|
||||
contents: read
|
||||
actions: read
|
||||
uses: ./.github/workflows/termux-verify.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
release: true
|
||||
|
||||
@@ -145,6 +154,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -165,6 +175,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -185,6 +196,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -205,6 +217,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -227,6 +240,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -247,6 +261,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
@@ -505,6 +520,7 @@ jobs:
|
||||
# stable/latest aliases move in the ordered publication pass.
|
||||
needs: [admit, docker]
|
||||
uses: ./.github/workflows/docker.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
release-phase: publish
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
@@ -520,6 +536,7 @@ jobs:
|
||||
packages: write
|
||||
id-token: write
|
||||
uses: ./.github/workflows/desktop-bundled-release.yml
|
||||
secrets: inherit
|
||||
with:
|
||||
tag: ${{ needs.admit.outputs.tag }}
|
||||
claim-tag: ${{ needs.admit.outputs.claim-tag }}
|
||||
|
||||
Reference in New Issue
Block a user