Skip to content

Commit 95c27e1

Browse files
authored
chore: OIDC Secrets (#984)
1 parent c7e36a0 commit 95c27e1

5 files changed

+15
-8
lines changed

.github/workflows/cf-worker-example-test.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
- name: Run Yarn
2424
run: yarn --immutable
2525
- name: Setup .dev.vars file
26-
run: echo "DEVCYCLE_SERVER_SDK_KEY=${{ secrets.DEVCYCLE_SERVER_SDK_KEY }}" > dev-apps/js-cloud-server/cloudflare-worker/.dev.vars
26+
run: echo "DEVCYCLE_SERVER_SDK_KEY=dvc_server_token_hash" > dev-apps/js-cloud-server/cloudflare-worker/.dev.vars
2727
- name: Run example app in background
2828
run: |
2929
yarn nx serve example-js-cloud-server-sdk-cf-worker &

.github/workflows/nx-affected-e2e.yml

+10-5
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,23 @@ on:
55
jobs:
66
build:
77
runs-on: ubuntu-latest
8+
permissions:
9+
contents: read
10+
id-token: write
11+
pull-requests: write
12+
issues: write
813
strategy:
914
matrix:
1015
node-version: [20.x]
1116
steps:
1217
- uses: actions/checkout@v4
1318
with:
1419
fetch-depth: 0
20+
- name: Set Secrets
21+
uses: DevCycleHQ/aws-secrets-action@main
22+
with:
23+
secrets_map: '{"E2E_NEXTJS_SERVER_KEY":"DEVCYCLE_GITHUB_js-sdks_E2E_NEXTJS_SERVER_KEY", "NEXT_PUBLIC_E2E_NEXTJS_CLIENT_KEY": "DEVCYCLE_GITHUB_js-sdks_NEXT_PUBLIC_E2E_NEXTJS_CLIENT_KEY", "DVC_E2E_SERVER_SDK_KEY": "DEVCYCLE_GITHUB_js-sdks_DVC_E2E_SERVER_SDK_KEY"}'
24+
aws_account_id: '134377926370'
1525
- name: Use Node.js ${{ matrix.node-version }}
1626
uses: actions/setup-node@v4
1727
with:
@@ -25,11 +35,6 @@ jobs:
2535
- name: Run Affected E2E Tests
2636
shell: bash
2737
run: yarn affected:e2e
28-
env:
29-
E2E_NEXTJS_SERVER_KEY: ${{ secrets.E2E_NEXTJS_SERVER_KEY }}
30-
NEXT_PUBLIC_E2E_NEXTJS_KEY: ${{ secrets.NEXT_PUBLIC_E2E_NEXTJS_CLIENT_KEY }}
31-
NEXT_PUBLIC_E2E_NEXTJS_CLIENT_KEY: ${{ secrets.NEXT_PUBLIC_E2E_NEXTJS_CLIENT_KEY }}
32-
DVC_E2E_SERVER_SDK_KEY: ${{ secrets.DVC_E2E_SERVER_SDK_KEY }}
3338
- name: Upload Playwright Report
3439
if: always()
3540
uses: actions/upload-artifact@v4

.github/workflows/release.yml

+2
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,8 @@ jobs:
3232
strategy:
3333
matrix:
3434
node-version: [20.x]
35+
env:
36+
GITHUB_TOKEN: ${{ secrets.AUTOMATION_USER_TOKEN }}
3537
steps:
3638
# Check out the repo with credentials that can bypass branch protection, and fetch git history instead of just latest commit
3739
- uses: actions/checkout@v4

.github/workflows/run-test-harness.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,4 +31,4 @@ jobs:
3131
with:
3232
sdks-to-test: nodejs,of-nodejs
3333
sdk-github-sha: ${{github.event.pull_request.head.sha}}
34-
github-token: ${{ secrets.TEST_HARNESS_GH_SECRET }}
34+
github-token: ${{ secrets.AUTOMATION_USER_TOKEN }}

.github/workflows/update-of-sdk.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ jobs:
1919
- name: Set Git author
2020
shell: bash
2121
run: |
22-
git config --global user.email "github-tracker-bot@taplytics.com"
22+
git config --global user.email "foundation-admin@devcycle.com"
2323
git config --global user.name "DevCycle Automation"
2424
2525
- name: Set branch name

0 commit comments

Comments
 (0)