Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(secret): update env values for secret origin ctn #615

Merged
merged 1 commit into from
Nov 11, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 21 additions & 1 deletion executor/linux/build.go
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ import (

"golang.org/x/sync/errgroup"

"github.com/go-vela/sdk-go/vela"
api "github.com/go-vela/server/api/types"
"github.com/go-vela/server/compiler/types/pipeline"
"github.com/go-vela/server/constants"
Expand Down Expand Up @@ -356,8 +357,27 @@ func (c *client) AssembleBuild(ctx context.Context) error {
}

c.Logger.Infof("creating %s secret", s.Origin.Name)

// fetch request token if id_request used in origin config
var requestToken string

if len(s.Origin.IDRequest) > 0 {
opts := &vela.RequestTokenOptions{
Image: s.Origin.Image,
Request: s.Origin.IDRequest,
Commands: len(s.Origin.Commands) > 0 || len(s.Origin.Entrypoint) > 0,
}

tkn, _, err := c.Vela.Build.GetIDRequestToken(c.build.GetRepo().GetOrg(), c.build.GetRepo().GetName(), c.build.GetNumber(), opts)
if err != nil {
return err
}

requestToken = tkn.GetToken()
}

// create the service
c.err = c.secret.create(ctx, s.Origin)
c.err = c.secret.create(ctx, s.Origin, requestToken)
if c.err != nil {
return fmt.Errorf("unable to create %s secret: %w", s.Origin.Name, c.err)
}
Expand Down
8 changes: 7 additions & 1 deletion executor/linux/secret.go
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
)

// create configures the secret plugin for execution.
func (s *secretSvc) create(ctx context.Context, ctn *pipeline.Container) error {
func (s *secretSvc) create(ctx context.Context, ctn *pipeline.Container, reqToken string) error {
// update engine logger with secret metadata
//
// https://pkg.go.dev/github.com/sirupsen/logrus#Entry.WithField
Expand All @@ -45,6 +45,12 @@
ctn.Environment["VELA_HOST"] = s.client.build.GetHost()
ctn.Environment["VELA_RUNTIME"] = s.client.build.GetRuntime()
ctn.Environment["VELA_VERSION"] = s.client.Version
ctn.Environment["VELA_OUTPUTS"] = "/vela/outputs/.env"
ctn.Environment["VELA_MASKED_OUTPUTS"] = "/vela/outputs/masked.env"

if len(reqToken) > 0 {
ctn.Environment["VELA_ID_TOKEN_REQUEST_TOKEN"] = reqToken
}

logger.Debug("setting up container")
// setup the runtime container
Expand Down Expand Up @@ -206,7 +212,7 @@
// https://pkg.go.dev/github.com/go-vela/sdk-go/vela#SecretService.Get
_secret, _, err = s.client.Vela.Secret.Get(secret.Engine, secret.Type, org, "*", key)
if err != nil {
return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)

Check failure on line 215 in executor/linux/secret.go

View workflow job for this annotation

GitHub Actions / golangci

[golangci] executor/linux/secret.go#L215

non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
Raw output
executor/linux/secret.go:215:37: non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
			return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)
			                                 ^
}

secret.Value = _secret.GetValue()
Expand All @@ -223,7 +229,7 @@
// https://pkg.go.dev/github.com/go-vela/sdk-go/vela#SecretService.Get
_secret, _, err = s.client.Vela.Secret.Get(secret.Engine, secret.Type, org, repo, key)
if err != nil {
return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)

Check failure on line 232 in executor/linux/secret.go

View workflow job for this annotation

GitHub Actions / golangci

[golangci] executor/linux/secret.go#L232

non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
Raw output
executor/linux/secret.go:232:37: non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
			return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)
			                                 ^
}

secret.Value = _secret.GetValue()
Expand All @@ -240,7 +246,7 @@
// https://pkg.go.dev/github.com/go-vela/sdk-go/vela#SecretService.Get
_secret, _, err = s.client.Vela.Secret.Get(secret.Engine, secret.Type, org, team, key)
if err != nil {
return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)

Check failure on line 249 in executor/linux/secret.go

View workflow job for this annotation

GitHub Actions / golangci

[golangci] executor/linux/secret.go#L249

non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
Raw output
executor/linux/secret.go:249:37: non-wrapping format verb for fmt.Errorf. Use `%w` to format errors (errorlint)
			return nil, fmt.Errorf("%s: %w", ErrUnableToRetrieve, err)
			                                 ^
}

secret.Value = _secret.GetValue()
Expand Down
2 changes: 1 addition & 1 deletion executor/linux/secret_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ func TestLinux_Secret_create(t *testing.T) {
t.Errorf("unable to create %s executor engine: %v", test.name, err)
}

err = _engine.secret.create(context.Background(), test.container)
err = _engine.secret.create(context.Background(), test.container, "")

if test.failure {
if err == nil {
Expand Down
Loading