Skip to content

feat(PLT-4422): add codeartifact-token action and opt-in CodeArtifact token for image-multiarch - #274

Closed
matiasozdy wants to merge 1 commit into
mainfrom
PLT-4422-codeartifact-token
Closed

matiasozdy wants to merge 1 commit into
mainfrom
PLT-4422-codeartifact-token

Conversation

@matiasozdy

@matiasozdy matiasozdy commented Oct 8, 2026 •

Copy link
Copy Markdown

Adds a way for CI to fetch AWS CodeArtifact tokens without the aws CLI, for the JFrog → CodeArtifact migration (PLT-4422, part of PLT-4416).

Path Change
shared-actions/codeartifact-token/action.yml New composite action. Uses astral-sh/setup-uv and boto3 to call GetAuthorizationToken with the job's AWS credentials, masks the token, sets the outputs token and pypi-index-url, and by default exports CODEARTIFACT_TOKEN, PIP_INDEX_URL and UV_INDEX_URL.
shared-actions/codeartifact-token/README.md Usage for CI installs and Docker builds; inputs and outputs.
.github/workflows/image-multiarch.yaml New optional input codeartifact (default false). When true, gets a token with the action above and passes it to both build-push-action steps as the BuildKit secret CODEARTIFACT_TOKEN, alongside build-secrets. reusable-workflows/image-multiarch/workflow.yaml is a symlink to this file, so it changes too.

Why

The ARC runner images (arc-ci-slim-base) ship no aws CLI or Python. The first JFrog sync run on ci-base-scale-set failed with exit 127 on aws ssm get-parameter (run). uv brings its own Python, and this pattern already runs on the same runners in Typeform/tools#339.

No change for existing callers

codeartifact defaults to false, so the token step is skipped and the extra secrets line renders empty. docker/build-push-action parses secrets with actions-toolkit Util.getList, which uses skipEmptyLines: true and drops empty items, so the secrets list is identical to today's.

Testing

  • Ran the action's run script, extracted from action.yml, locally against the live typeform domain: exit 0, token masked, all 5 outputs and env vars written. The PIP_INDEX_URL it built served an internal package's index page with that token.
  • The same script with a stubbed token, with export-env set to true and false: masking and outputs are correct, and nothing is exported with false.
  • Not yet run in GitHub Actions. The first pilot repo (PLT-4422) will call the action from this branch first, which tests the runner's IAM credentials on ARC. The image-multiarch path can only be exercised after a v1 release, because the workflow references the action @v1 like the other shared actions.

Release

After merge, the release workflow moves v1. Callers are unaffected until they set codeartifact: true.

🤖 Generated with Claude Code

… token for image-multiarch

Repos are moving their Python packages from JFrog to AWS CodeArtifact
(PLT-4416). CI needs a CodeArtifact token, but the ARC runner images have
no aws CLI (seen as exit 127 in Typeform/tools run 37763935692).

shared-actions/codeartifact-token gets the token with uv and boto3 using
the job's AWS credentials, masks it, sets outputs, and by default exports
CODEARTIFACT_TOKEN, PIP_INDEX_URL and UV_INDEX_URL.

image-multiarch gains an opt-in `codeartifact` input that passes the token
as the BuildKit secret CODEARTIFACT_TOKEN. It defaults to false; with it
off, the extra secrets line is empty and docker/build-push-action's input
parser drops empty lines (skipEmptyLines and filter in actions-toolkit
Util.getList), so existing callers build exactly as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@matiasozdy
matiasozdy requested a review from a team as a code owner October 8, 2026 13:43
@pr-auditor

pr-auditor Bot commented Oct 8, 2026

Copy link
Copy Markdown

✅ Security Analysis Results

No security issues found. 3 files reviewed.


@pr-auditor rescan to re-run · Powered by Claude Sonnet 5 · Docs · #security-engineering-team

@matiasozdy

Copy link
Copy Markdown
Author

Closing: moving this to an internal repository.

@matiasozdy matiasozdy closed this Oct 8, 2026
@matiasozdy
matiasozdy deleted the PLT-4422-codeartifact-token branch October 8, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant