fix(accounts): offer a whole workflow or the step alone as a trusted workflow's example - #616
Merged
Merged
Conversation
… example The example usage for a trusted GitHub workflow was a fragment of a job, `env:` and `steps:` at column zero with permissions in a comment, so pasting it into a workflow put the keys at the wrong level: at the top level `steps` is invalid, and under `jobs:` they become jobs of their own. It is now a complete workflow to save under .github/workflows/: one job with runs-on, `id-token: write`, the proxy's S3 endpoint, the sign-in step and a first `aws s3 ls`. The example is built from the trust's subject, so a trust pinned to an environment gets `environment:` on the job, without which GitHub puts the ref in the token's subject and the trust doesn't match; a trust pinned to a ref says which ref to run it on. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Claude finished @alukach's task in 24s —— View job ✅ No blocking issues — safe to merge. I read the diff for
Simplify (ponytail)
DocsThe description names ADR-014 (still holds, since the step and 💰 Estimated review cost: $0.13 · 0m23s · 5 turns |
…workflow and the step
The example usage for a trusted GitHub workflow now offers both forms behind a segmented control. "Full Workflow" sets AWS_ENDPOINT_URL_S3 once for the whole workflow; "Step" is the configure-aws-credentials step alone, setting AWS_ENDPOINT_URL_S3 on itself, with comments saying what the surrounding job needs. In both, `audience` and `sts-endpoint` read the proxy's address from `${{ env.AWS_ENDPOINT_URL_S3 }}` instead of repeating it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…itch Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
"Example usage" on a trusted GitHub workflow handed out a fragment of a job:
env:andsteps:at column zero, withpermissions: { id-token: write }left in a comment. It didn't drop into a workflow: at the top levelstepsis invalid, and pasted underjobs:the keys turn into jobs namedenvandsteps, leaving the real job with nothing to run. That's what happened on the first hand-written workflow against staging. It also ignored which subject the trust names, so a trust pinned to an environment got an example whose token would carry the ref instead, and would be refused. Part of #491.What
The dialog now has a switch between two forms, both naming the proxy once in
AWS_ENDPOINT_URL_S3and reading it back in the sign-in step'swith:as${{ env.AWS_ENDPOINT_URL_S3 }}(foraudience, and with/.stsappended forsts-endpoint):githubWorkflow(proxyOrigin, accountId, subject)returns a complete workflow to save under.github/workflows/.AWS_ENDPOINT_URL_S3is set in a workflow-levelenv:, so every step's S3 client reaches the proxy. One job,data, hasruns-on,permissions(id-token: write,contents: read), theconfigure-aws-credentials@v6sign-in step, and a firstaws s3 ls s3://{owner}/to show the credentials working.githubWorkflowStep(proxyOrigin, accountId, subject)returns the sign-in step alone, for a workflow that already exists, withAWS_ENDPOINT_URL_S3set in the step's ownenv:. A step'senvreaches only that step, so two comments above it say what the job around it needs:id-token: write(plus the environment, for a trust pinned to one), andAWS_ENDPOINT_URL_S3on the job for later steps to reach the proxy.Both forms are built from one shared
signInStep. Either way:environment:on the job (JSON-quoted, since an environment name may hold a space). Without it GitHub puts the ref in the token's subject, and the trust doesn't match.on: workflow_dispatchline which ref to run it from (full workflow only).ExampleUsagetakescodeas before, or a map of labelled forms, in which case aSegmentedControlabove the code chooses between them and the copy button takes whichever is showing.ServiceAccountDetailpasses both forms for each trust, and the intro now reads "In the repository{subject}names, save the full workflow under.github/workflows/, or add the step to a job of your own:".Stories
On this branch's deploy:
ExampleUsage› GithubWorkflow (opens on Full Workflow): https://source-coop-ui-git-fix-github-workflow-example-radiantearth.vercel.app/?path=/story/features-service-accounts-exampleusage--github-workflowExampleUsage› GithubWorkflowStep (new, opens on Step): https://source-coop-ui-git-fix-github-workflow-example-radiantearth.vercel.app/?path=/story/features-service-accounts-exampleusage--github-workflow-stepExampleUsage› GithubWorkflowInAnEnvironment (new): https://source-coop-ui-git-fix-github-workflow-example-radiantearth.vercel.app/?path=/story/features-service-accounts-exampleusage--github-workflow-in-an-environmentExampleUsage› Mobile: https://source-coop-ui-git-fix-github-workflow-example-radiantearth.vercel.app/?path=/story/features-service-accounts-exampleusage--mobileTesting
service-account-usage.test.ts: the workflow setsAWS_ENDPOINT_URL_S3in a top-levelenvand has one job holdingruns-on,permissionswithid-token: writeand the sign-in step, nested where GitHub reads them (asserted on the exact indented lines, since nesting is the bug);with:reads${{ env.AWS_ENDPOINT_URL_S3 }}; a ref trust adds noenvironment, while an environment trust puts it on the job. The step stands alone withenvbesidewith, and names the environment in its comment when the trust is pinned to one. 6 pass.prod westparsed withjs-yaml: the workflow's top-levelenv, the job'senvironmentand the step'swith, and the step's ownenvandwith.src/stories.smoke.test.tsx195 pass;npm run type-checkis clean.configure-aws-credentialschecks the credentials withGetCallerIdentity. Thatwith:can read a step's ownenvcomes from GitHub's documented context availability (envis available injobs.<job_id>.steps.with), not from a run.Docs and ADRs
Checked ADR-014 (source-cooperative/data.source.coop): the step and the
RoleArnit names are unchanged, so it still holds. docs.source.coop: the automated-access guide (source-cooperative/docs.source.coop#37) has its GitHub Actions section marked "coming soon", and should use this file when it's written.🤖 Generated with Claude Code