Skip to content

Use a crates.io API token for the release workflow - #43

Merged
scouten-adobe merged 1 commit into
mainfrom
scouten-adobe-crates-io-token
Sep 29, 2026
Merged

scouten-adobe merged 1 commit into
mainfrom
scouten-adobe-crates-io-token

Conversation

@scouten-adobe

Copy link
Copy Markdown
Member

Follow-up to #42.

Trusted Publishing needs a one-time OIDC configuration on the crates.io crate settings page. That's more ceremony than is warranted for getting 0.3.0 out, so this switches the release workflow to a plain CARGO_REGISTRY_TOKEN secret — the only setup is pasting a token into repository settings.

Changes

  • Publish using the CARGO_REGISTRY_TOKEN secret instead of obtaining a short-lived token via rust-lang/crates-io-auth-action.
  • Drop the now-unneeded id-token: write permission.
  • Fail fast when the secret is missing. Previously a misconfigured secret would only surface after the ~230 MB model download and the full test run; now it's the first step after checkout.
  • Document the token setup in rust/RELEASING.md, and keep Trusted Publishing documented as the alternative for whenever we want to stop storing a long-lived credential.

The crates-io environment is retained, and the docs now recommend storing the token as an environment secret rather than a repository secret, so it's only exposed to jobs that opt into that environment — and so a required-reviewer rule can be added later if desired.

Setup required before the first automated release

  1. Create a crates.io API token scoped to publish-update, restricted to the trustmark crate.
  2. Create a crates-io environment under Settings → Environments (the repo currently has none).
  3. Add the token as a CARGO_REGISTRY_TOKEN secret on that environment.

Validation

  • Workflow parses as valid YAML; job structure, permissions, and step order verified.
  • The credential guard was exercised locally for both the set and unset cases.
  • No changes to the CI workflow or crate source.

Trusted Publishing requires a one-time OIDC setup on the crates.io crate
settings, which is more ceremony than is warranted right now. Switch to a
CARGO_REGISTRY_TOKEN secret, which only needs to be pasted into the repository
settings.

- Publish using the CARGO_REGISTRY_TOKEN secret instead of obtaining a
  short-lived token via rust-lang/crates-io-auth-action.
- Drop the now-unneeded id-token: write permission.
- Fail fast when the secret is missing, rather than after the ~230 MB model
  download and full test run.
- Document the token setup, and keep Trusted Publishing documented as the
  alternative for whenever we want to stop storing a long-lived credential.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@scouten-adobe
scouten-adobe merged commit ed5ea84 into main Sep 29, 2026
8 checks passed
@scouten-adobe
scouten-adobe deleted the scouten-adobe-crates-io-token branch September 29, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants