Repository navigation
feat(PLT-4422): add codeartifact-token action and opt-in CodeArtifact token for image-multiarch - #274
Closed
matiasozdy wants to merge 1 commit into
Closed
matiasozdy wants to merge 1 commit into
matiasozdy wants to merge 1 commit into
Conversation
… token for image-multiarch Repos are moving their Python packages from JFrog to AWS CodeArtifact (PLT-4416). CI needs a CodeArtifact token, but the ARC runner images have no aws CLI (seen as exit 127 in Typeform/tools run 37763935692). shared-actions/codeartifact-token gets the token with uv and boto3 using the job's AWS credentials, masks it, sets outputs, and by default exports CODEARTIFACT_TOKEN, PIP_INDEX_URL and UV_INDEX_URL. image-multiarch gains an opt-in `codeartifact` input that passes the token as the BuildKit secret CODEARTIFACT_TOKEN. It defaults to false; with it off, the extra secrets line is empty and docker/build-push-action's input parser drops empty lines (skipEmptyLines and filter in actions-toolkit Util.getList), so existing callers build exactly as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
✅ Security Analysis ResultsNo security issues found. 3 files reviewed.
|
Author
|
Closing: moving this to an internal repository. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a way for CI to fetch AWS CodeArtifact tokens without the
awsCLI, for the JFrog → CodeArtifact migration (PLT-4422, part of PLT-4416).shared-actions/codeartifact-token/action.ymlastral-sh/setup-uvand boto3 to callGetAuthorizationTokenwith the job's AWS credentials, masks the token, sets the outputstokenandpypi-index-url, and by default exportsCODEARTIFACT_TOKEN,PIP_INDEX_URLandUV_INDEX_URL.shared-actions/codeartifact-token/README.md.github/workflows/image-multiarch.yamlcodeartifact(defaultfalse). Whentrue, gets a token with the action above and passes it to bothbuild-push-actionsteps as the BuildKit secretCODEARTIFACT_TOKEN, alongsidebuild-secrets.reusable-workflows/image-multiarch/workflow.yamlis a symlink to this file, so it changes too.Why
The ARC runner images (
arc-ci-slim-base) ship noawsCLI or Python. The first JFrog sync run onci-base-scale-setfailed with exit 127 onaws ssm get-parameter(run).uvbrings its own Python, and this pattern already runs on the same runners in Typeform/tools#339.No change for existing callers
codeartifactdefaults tofalse, so the token step is skipped and the extrasecretsline renders empty.docker/build-push-actionparsessecretswith actions-toolkitUtil.getList, which usesskipEmptyLines: trueand drops empty items, so the secrets list is identical to today's.Testing
runscript, extracted fromaction.yml, locally against the livetypeformdomain: exit 0, token masked, all 5 outputs and env vars written. ThePIP_INDEX_URLit built served an internal package's index page with that token.export-envset totrueandfalse: masking and outputs are correct, and nothing is exported withfalse.image-multiarchpath can only be exercised after av1release, because the workflow references the action@v1like the other shared actions.Release
After merge, the
releaseworkflow movesv1. Callers are unaffected until they setcodeartifact: true.🤖 Generated with Claude Code