fix(ci): give the stable-release reusable workflows their environment secrets

stable-release.yml called desktop-bundled-release.yml, docker.yml and
termux-verify.yml without `secrets: inherit`, so every job inside them that
declares `environment: release-signing` (or container-publish) attached its
deployment and read the environment's `vars`, but resolved `secrets.*` to the
empty string. The signed-candidate legs died at "Archive every pinned input"
with `missing env CLOUDFLARE_R2_ACCESS_KEY_ID`; the docker publish legs and
the termux packaging checks would have failed the same way.

A called workflow receives no secrets by default, and a job-level
`environment:` inside it is required but not sufficient: a caller job that
`uses:` a reusable workflow cannot declare `environment:` at all, so
`secrets: inherit` is the only mechanism that can carry them
(actions/runner#1490).

`secrets: inherit` is added only where the callee reads a protected
environment's secrets. ci.yaml, nix, pm-bundle, windows-venv-e2e and the
install-e2e chain reference none, and ci.yaml must stay secret-free by its own
header (it runs PR-controlled code).
This commit is contained in:
ethernet
2026-09-29 09:40:09 -04:00
parent fc042f1d67
commit ee5f49b943
2 changed files with 22 additions and 0 deletions
@@ -58,6 +58,11 @@ name: Desktop Bundled Release
# Manual dispatch selects a tag or a pushed full commit. Commit dispatches
# use the default-branch workflow and require maintainer permission.
#
# Callers must dispatch with `secrets: inherit`: a called workflow receives
# no secrets by default, and a job-level `environment:` alone attaches the
# deployment and exposes `vars` but NOT that environment's secrets
# (actions/runner#1490).
#
# R2 secrets (repo-level or the release-signing environment): the R2
# account id + an R2 API token (S3-compatible) with read/write on the
# release bucket; CLOUDFLARE_R2_BUCKET and CLOUDFLARE_R2_PUBLIC_URL are
+17
View File
@@ -17,6 +17,13 @@ on:
permissions:
contents: read
# Every reusable workflow called below inherits secrets (`secrets: inherit`)
# because their release-signing jobs need protected-environment secrets. A
# called workflow only sees them when the caller inherits AND the called job
# declares the environment: the job-level `environment:` alone attaches the
# deployment and exposes `vars`, but leaves `secrets.*` empty
# (actions/runner#1490). ci.yaml is deliberately excluded — it runs
# PR-controlled code and must stay secret-free.
concurrency:
group: stable-release
cancel-in-progress: false
@@ -76,6 +83,7 @@ jobs:
if: >-
!cancelled() && needs.admit.result == 'success'
uses: ./.github/workflows/docker.yml
secrets: inherit
with:
release-phase: test
skip-tests: ${{ needs.admit.outputs.skip-tests == 'true' }}
@@ -109,6 +117,7 @@ jobs:
contents: read
actions: read
uses: ./.github/workflows/termux-verify.yml
secrets: inherit
with:
release: true
@@ -145,6 +154,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -165,6 +175,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -185,6 +196,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -205,6 +217,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -227,6 +240,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -247,6 +261,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}
@@ -505,6 +520,7 @@ jobs:
# stable/latest aliases move in the ordered publication pass.
needs: [admit, docker]
uses: ./.github/workflows/docker.yml
secrets: inherit
with:
release-phase: publish
tag: ${{ needs.admit.outputs.tag }}
@@ -520,6 +536,7 @@ jobs:
packages: write
id-token: write
uses: ./.github/workflows/desktop-bundled-release.yml
secrets: inherit
with:
tag: ${{ needs.admit.outputs.tag }}
claim-tag: ${{ needs.admit.outputs.claim-tag }}