|
24 | 24 | PYTHONVERSION: "3.11.8"
|
25 | 25 | DOTNETVERSION: "8.0.x"
|
26 | 26 | JAVAVERSION: "11"
|
27 |
| - AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }} |
28 | 27 | AWS_REGION: us-west-2
|
29 |
| - AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }} |
30 |
| - AWS_UPLOAD_ROLE_ARN: ${{ secrets.AWS_UPLOAD_ROLE_ARN }} |
31 |
| - CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} |
32 |
| - JAVA_SIGNING_KEY: ${{ secrets.JAVA_SIGNING_KEY }} |
33 |
| - JAVA_SIGNING_KEY_ID: ${{ secrets.JAVA_SIGNING_KEY_ID }} |
34 |
| - JAVA_SIGNING_PASSWORD: ${{ secrets.JAVA_SIGNING_PASSWORD }} |
35 |
| - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} |
36 |
| - NUGET_PUBLISH_KEY: ${{ secrets.NUGET_PUBLISH_KEY }} |
37 |
| - OSSRH_PASSWORD: ${{ secrets.OSSRH_PASSWORD }} |
38 |
| - OSSRH_USERNAME: ${{ secrets.OSSRH_USERNAME }} |
39 | 28 | PULUMI_API: https://api.pulumi-staging.io
|
40 |
| - PULUMI_BOT_TOKEN: ${{ secrets.PULUMI_BOT_TOKEN }} |
41 |
| - PYPI_API_TOKEN: ${{ secrets.PYPI_API_TOKEN }} |
42 |
| - RELEASE_BOT_ENDPOINT: ${{ secrets.RELEASE_BOT_ENDPOINT }} |
43 |
| - RELEASE_BOT_KEY: ${{ secrets.RELEASE_BOT_KEY }} |
44 | 29 |
|
45 | 30 | jobs:
|
46 | 31 | prerequisites:
|
|
54 | 39 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
55 | 40 | with:
|
56 | 41 | lfs: true
|
57 |
| - - id: esc-secrets |
58 |
| - name: Map environment to ESC outputs |
59 |
| - uses: ./.github/actions/esc-action |
| 42 | + - env: |
| 43 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 44 | + ESC_ACTION_OIDC_AUTH: "true" |
| 45 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 46 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 47 | + id: esc-secrets |
| 48 | + name: Fetch secrets from ESC |
| 49 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
60 | 50 | - id: version
|
61 | 51 | name: Set Provider Version
|
62 | 52 | uses: pulumi/provider-version-action@f96d032a2758fdda7939e5728eff6c0d980ae894 # v1.6.0
|
@@ -187,9 +177,14 @@ jobs:
|
187 | 177 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
188 | 178 | with:
|
189 | 179 | lfs: true
|
190 |
| - - id: esc-secrets |
191 |
| - name: Map environment to ESC outputs |
192 |
| - uses: ./.github/actions/esc-action |
| 180 | + - env: |
| 181 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 182 | + ESC_ACTION_OIDC_AUTH: "true" |
| 183 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 184 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 185 | + id: esc-secrets |
| 186 | + name: Fetch secrets from ESC |
| 187 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
193 | 188 | - id: version
|
194 | 189 | name: Set Provider Version
|
195 | 190 | uses: pulumi/provider-version-action@f96d032a2758fdda7939e5728eff6c0d980ae894 # v1.6.0
|
@@ -336,9 +331,14 @@ jobs:
|
336 | 331 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
337 | 332 | with:
|
338 | 333 | lfs: true
|
339 |
| - - id: esc-secrets |
340 |
| - name: Map environment to ESC outputs |
341 |
| - uses: ./.github/actions/esc-action |
| 334 | + - env: |
| 335 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 336 | + ESC_ACTION_OIDC_AUTH: "true" |
| 337 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 338 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 339 | + id: esc-secrets |
| 340 | + name: Fetch secrets from ESC |
| 341 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
342 | 342 | - name: check if this commit needs release
|
343 | 343 | if: ${{ env.RELEASE_BOT_ENDPOINT != '' }}
|
344 | 344 | uses: pulumi/action-release-by-pr-label@main
|
@@ -375,9 +375,14 @@ jobs:
|
375 | 375 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
376 | 376 | with:
|
377 | 377 | lfs: true
|
378 |
| - - id: esc-secrets |
379 |
| - name: Map environment to ESC outputs |
380 |
| - uses: ./.github/actions/esc-action |
| 378 | + - env: |
| 379 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 380 | + ESC_ACTION_OIDC_AUTH: "true" |
| 381 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 382 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 383 | + id: esc-secrets |
| 384 | + name: Fetch secrets from ESC |
| 385 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
381 | 386 | - id: version
|
382 | 387 | name: Set Provider Version
|
383 | 388 | uses: pulumi/provider-version-action@f96d032a2758fdda7939e5728eff6c0d980ae894 # v1.6.0
|
@@ -500,9 +505,14 @@ jobs:
|
500 | 505 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
501 | 506 | with:
|
502 | 507 | lfs: true
|
503 |
| - - id: esc-secrets |
504 |
| - name: Map environment to ESC outputs |
505 |
| - uses: ./.github/actions/esc-action |
| 508 | + - env: |
| 509 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 510 | + ESC_ACTION_OIDC_AUTH: "true" |
| 511 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 512 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 513 | + id: esc-secrets |
| 514 | + name: Fetch secrets from ESC |
| 515 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
506 | 516 | - id: version
|
507 | 517 | name: Set Provider Version
|
508 | 518 | uses: pulumi/provider-version-action@f96d032a2758fdda7939e5728eff6c0d980ae894 # v1.6.0
|
@@ -576,9 +586,14 @@ jobs:
|
576 | 586 | uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
|
577 | 587 | with:
|
578 | 588 | lfs: true
|
579 |
| - - id: esc-secrets |
580 |
| - name: Map environment to ESC outputs |
581 |
| - uses: ./.github/actions/esc-action |
| 589 | + - env: |
| 590 | + ESC_ACTION_ENVIRONMENT: github-secrets/${{ github.repository_owner }}-${{ github.event.repository.name }} |
| 591 | + ESC_ACTION_OIDC_AUTH: "true" |
| 592 | + ESC_ACTION_OIDC_ORGANIZATION: pulumi |
| 593 | + ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization |
| 594 | + id: esc-secrets |
| 595 | + name: Fetch secrets from ESC |
| 596 | + uses: pulumi/esc-action@9eb774255b1a4afb7855678ae8d4a77359da0d9b |
582 | 597 | - id: version
|
583 | 598 | name: Set Provider Version
|
584 | 599 | uses: pulumi/provider-version-action@f96d032a2758fdda7939e5728eff6c0d980ae894 # v1.6.0
|
|
0 commit comments