Skip to content

ci: Add support for OIDC - #2053

Merged
sayboras merged 1 commit into
mainfrom
pr/aanm/quay-oidc-robot-variables
Sep 29, 2026
Merged

sayboras merged 1 commit into
mainfrom
pr/aanm/quay-oidc-robot-variables

Conversation

@aanm

@aanm aanm commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

This commit adds support for OIDC, replacing long-lived tokens. Quay.io
has been configured accordingly.

The token expires after one hour, so it is minted after each build
rather than once at the start of the job.

The robot account names are read from the QUAY_ROBOT_CI and
QUAY_ROBOT_RELEASE variables, defined on the GitHub environments the
jobs pin rather than at repository or organisation level, so the value a
job receives is the one belonging to its environment. The environment
name also forms the OIDC subject that the robot is configured to trust,
so renaming an environment breaks the login.

@aanm
aanm force-pushed the pr/aanm/quay-oidc-robot-variables branch from 3b5aa58 to 789f6cb Compare September 25, 2026 13:29
This commit adds support for OIDC, replacing long-lived tokens. Quay.io
has been configured accordingly.

The token expires after one hour, so it is minted after each build
rather than once at the start of the job.

The robot account names are read from the QUAY_ROBOT_CI and
QUAY_ROBOT_RELEASE variables, defined on the GitHub environments the
jobs pin rather than at repository or organisation level, so the value a
job receives is the one belonging to its environment. The environment
name also forms the OIDC subject that the robot is configured to trust,
so renaming an environment breaks the login.

Signed-off-by: André Martins <andre@cilium.io>
@aanm
aanm force-pushed the pr/aanm/quay-oidc-robot-variables branch from 789f6cb to 5983dc5 Compare September 25, 2026 14:47

@sayboras sayboras left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot for your kind help, just a note that we don't have ariane enabled for this repo, so the changes are actually not verified due to pull request target settings.

@aanm

aanm commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Tested with a temporary DO NOT MERGE commit that switches build-envoy-image-ci.yaml to pull_request: https://github.com/cilium/proxy/actions/runs/36422919990. The run got the robot token through OIDC and pushed quay.io/cilium/cilium-envoy-dev:a4198916e1ef6f0246622b3d000070f498450615@sha256:20b1f2febe3187d36ea6e1ae5084f0d2e5aaae60fa5a849f73ac97483958d6e7, the digest cosign signed and the SBOM is attached to. The builder image already existed, so its OIDC login step was skipped.

@aanm
aanm force-pushed the pr/aanm/quay-oidc-robot-variables branch from a419891 to 5983dc5 Compare September 28, 2026 12:51
@aanm
aanm requested a review from sayboras September 28, 2026 13:11
@sayboras
sayboras marked this pull request as ready for review September 28, 2026 13:48
@sayboras
sayboras requested a review from a team as a code owner September 28, 2026 13:48

@sayboras sayboras left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot 💯

Comment thread .github/workflows/build-envoy-image-ci.yaml
@sayboras
sayboras merged commit c3a2a1f into main Sep 29, 2026
18 of 20 checks passed
@sayboras
sayboras deleted the pr/aanm/quay-oidc-robot-variables branch September 29, 2026 08:38
@aanm
aanm requested a review from sayboras September 29, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants