You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Extend overture-releaser GitHub App with Actions:write and install on OvertureMaps/docs #689
Manual prerequisite for #679, refs OvertureMaps/docs#493. docs-publish.yml (added in #690) dispatches a production docs rebuild on OvertureMaps/docs when an overture-schema release publishes, but no app installed on this org can currently call another repo's Actions API.
Install overture-releaser additionally on OvertureMaps/docs (it's schema-repo-only today).
No new secrets are needed: docs-publish.yml reuses the same PEM already in AWS Secrets Manager (omf-github-terraform/releaser/pem, secret RELEASE_PUBLISHER_APP_PEM, read via the gha-releaser-secrets-reader OIDC role) and the same client ID (Iv23lijru2e660v1zJQO) that release-trigger.yaml already uses, just requesting permission-actions: write instead of permission-contents: write when minting the installation token.
Note
This deliberately bends omf-github-terraform/docs/github-apps.md's "one app per concern" convention (widening overture-releaser instead of provisioning a narrower new app). That's an explicit call by the user to avoid app sprawl for a second release-triggered automation on the same repo, not an oversight.
Done when
overture-releaser has Actions: write added in its org app settings
overture-releaser is installed on OvertureMaps/docs
The next overture-schema release confirms docs-publish.yml successfully dispatches production_deploy_documentation.yml on OvertureMaps/docs
Manual prerequisite for #679, refs OvertureMaps/docs#493.
docs-publish.yml(added in #690) dispatches a production docs rebuild onOvertureMaps/docswhen anoverture-schemarelease publishes, but no app installed on this org can currently call another repo's Actions API.What to do
Extend the existing
overture-releaserapp (org settings: https://github.com/organizations/OvertureMaps/settings/apps/overture-releaser) rather than provisioning a new one:Actions: writetooverture-releaser(it currently hascontents: writeonly, used byrelease-trigger.yaml, see Provisionoverture-release-publisherGitHub App for Phase 3 release publishing #637).overture-releaseradditionally onOvertureMaps/docs(it's schema-repo-only today).No new secrets are needed:
docs-publish.ymlreuses the same PEM already in AWS Secrets Manager (omf-github-terraform/releaser/pem, secretRELEASE_PUBLISHER_APP_PEM, read via thegha-releaser-secrets-readerOIDC role) and the same client ID (Iv23lijru2e660v1zJQO) thatrelease-trigger.yamlalready uses, just requestingpermission-actions: writeinstead ofpermission-contents: writewhen minting the installation token.Note
This deliberately bends omf-github-terraform/docs/github-apps.md's "one app per concern" convention (widening
overture-releaserinstead of provisioning a narrower new app). That's an explicit call by the user to avoid app sprawl for a second release-triggered automation on the same repo, not an oversight.Done when
overture-releaserhasActions: writeadded in its org app settingsoverture-releaseris installed onOvertureMaps/docsoverture-schemarelease confirmsdocs-publish.ymlsuccessfully dispatchesproduction_deploy_documentation.ymlonOvertureMaps/docs