Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 26 additions & 1 deletion .github/actions/aws-ecr-auth/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ inputs:
role-to-assume:
description: 'IAM role to assume'
required: true
# Fail-closed by default: an empty role fails the job unless the caller explicitly
# opts in; only secretless Dependabot/fork PR runs are allowed to skip.
skip-when-missing-role:
description: 'Skip authentication when role-to-assume is empty (secretless Dependabot/fork PR runs only).'
required: false
default: 'false'
aws-region:
description: 'AWS region'
required: true
Expand All @@ -19,14 +25,33 @@ inputs:
runs:
using: "composite"
steps:
- name: Validate role input
id: validate
shell: bash
env:
ROLE_TO_ASSUME: ${{ inputs.role-to-assume }}
SKIP_WHEN_MISSING: ${{ inputs.skip-when-missing-role }}
run: |
if [[ -n "$ROLE_TO_ASSUME" ]]; then
echo "auth=true" >> "$GITHUB_OUTPUT"
elif [[ "$SKIP_WHEN_MISSING" == "true" ]]; then
echo "auth=false" >> "$GITHUB_OUTPUT"
echo "role-to-assume empty with skip-when-missing-role=true; skipping ECR authentication."
else
echo "::error::role-to-assume is empty (missing or renamed secret?); failing closed. Pass skip-when-missing-role=true only for secretless Dependabot/fork PR runs."
exit 1
fi

- name: Configure AWS credentials using OIDC
if: steps.validate.outputs.auth == 'true'
uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4.0.2
with:
role-to-assume: ${{ inputs.role-to-assume }}
aws-region: ${{ inputs.aws-region }}
- name: Authenticate to ECR
id: login-ecr
if: steps.validate.outputs.auth == 'true'
uses: aws-actions/amazon-ecr-login@062b18b96a7aff071d4dc91bc00c4c1a7945b076 # v2.0.1
with:
registry-type: ${{ inputs.registry-type }}
registries: ${{ inputs.registries }}
registries: ${{ inputs.registries }}
21 changes: 21 additions & 0 deletions .github/actions/build-devenv-docker/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,25 @@ inputs:
runs:
using: composite
steps:
- name: Validate ECR inputs
id: validate
shell: bash
env:
CCV_IAM_ROLE: ${{ inputs.ccv-iam-role }}
JD_REGISTRY: ${{ inputs.jd-registry }}
# Dependabot and fork PR runs get no repo secrets; these builds pull only public base images.
SECRETLESS_RUN: ${{ github.event_name == 'pull_request' && (github.actor == 'dependabot[bot]' || github.event.pull_request.head.repo.fork == true) }}
run: |
if [[ -n "$CCV_IAM_ROLE" && -n "$JD_REGISTRY" ]]; then
echo "auth=true" >> "$GITHUB_OUTPUT"
elif [[ -z "$CCV_IAM_ROLE" && -z "$JD_REGISTRY" && "$SECRETLESS_RUN" == "true" ]]; then
echo "auth=false" >> "$GITHUB_OUTPUT"
echo "Dependabot/fork PR without repo secrets; skipping ECR authentication (builds pull only public base images)."
else
echo "::error::ECR inputs incomplete (ccv-iam-role/jd-registry); failing closed so auth cannot silently degrade."
exit 1
fi

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1

Expand All @@ -21,13 +40,15 @@ runs:
just-version: '1.40.0'

- name: Authenticate to AWS ECR
if: steps.validate.outputs.auth == 'true'
uses: ./.github/actions/aws-ecr-auth
with:
role-to-assume: ${{ inputs.ccv-iam-role }}
aws-region: us-east-1
registry-type: public

- name: Authenticate to AWS ECR (JD)
if: steps.validate.outputs.auth == 'true'
uses: ./.github/actions/aws-ecr-auth
with:
role-to-assume: ${{ inputs.ccv-iam-role }}
Expand Down
76 changes: 76 additions & 0 deletions .github/actions/setup-github-token/action.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
name: Setup GitHub Token
description: >-
Calls smartcontractkit/.github's GATI token setup, or skips it when this is a
Dependabot/fork PR run with no repo secrets (all module dependencies here are
public). Any partial configuration, or missing secrets on a trusted run
(push, human PR, merge queue), fails closed so auth cannot silently degrade.

inputs:
aws-role-arn:
description: ARN of role capable of getting token from GATI
required: false
default: ''
aws-lambda-url:
description: URL of GATI lambda function
required: false
default: ''
aws-region:
description: AWS region
required: false
default: ''
aws-role-duration-seconds:
description: Duration of role in seconds
required: false
default: '900'
role-session-name:
description: Session name to use when assuming the role.
required: false
default: '${{ github.run_id }}-${{ github.run_number }}-${{ github.job }}'
set-git-config:
description: Set git config
required: false
default: 'false'

outputs:
access-token:
description: The github access token that has permissions reflecting the current AWS role value
value: ${{ steps.gati.outputs.access-token }}

runs:
using: composite
steps:
- name: Validate GATI inputs
id: validate
shell: bash
env:
AWS_ROLE_ARN: ${{ inputs.aws-role-arn }}
AWS_LAMBDA_URL: ${{ inputs.aws-lambda-url }}
AWS_REGION: ${{ inputs.aws-region }}
# Dependabot and fork PR runs get no repo secrets; every other run is trusted.
SECRETLESS_RUN: ${{ github.event_name == 'pull_request' && (github.actor == 'dependabot[bot]' || github.event.pull_request.head.repo.fork == true) }}
run: |
present=0
if [[ -n "$AWS_ROLE_ARN" ]]; then present=$((present + 1)); fi
if [[ -n "$AWS_LAMBDA_URL" ]]; then present=$((present + 1)); fi
if [[ -n "$AWS_REGION" ]]; then present=$((present + 1)); fi
if [[ "$present" -eq 3 ]]; then
echo "run=true" >> "$GITHUB_OUTPUT"
elif [[ "$present" -eq 0 && "$SECRETLESS_RUN" == "true" ]]; then
echo "run=false" >> "$GITHUB_OUTPUT"
echo "Dependabot/fork PR without repo secrets; skipping GATI token setup."
else
echo "::error::GATI inputs incomplete (${present}/3 set); failing closed so auth cannot silently degrade."
exit 1
fi

- name: Setup GitHub Token
id: gati
if: steps.validate.outputs.run == 'true'
uses: smartcontractkit/.github/actions/setup-github-token@ef78fa97bf3c77de6563db1175422703e9e6674f # setup-github-token@0.2.1

Check warning on line 69 in .github/actions/setup-github-token/action.yaml

View workflow job for this annotation

GitHub Actions / Validate Workflow Changes

1. Trusted actions should use a major version tag, if available. (trusted-tag-ref / warning)
with:
aws-role-arn: ${{ inputs.aws-role-arn }}
aws-lambda-url: ${{ inputs.aws-lambda-url }}
aws-region: ${{ inputs.aws-region }}
aws-role-duration-seconds: ${{ inputs.aws-role-duration-seconds }}
role-session-name: ${{ inputs.role-session-name }}
set-git-config: ${{ inputs.set-git-config }}
13 changes: 7 additions & 6 deletions .github/workflows/golangci-lint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,20 +16,21 @@
id-token: write
contents: read
steps:
# Local actions need the repo on disk, so checkout must precede setup-github-token.
- name: Checkout code
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0

Check warning on line 21 in .github/workflows/golangci-lint.yaml

View workflow job for this annotation

GitHub Actions / Validate Workflow Changes

1. Trusted actions should use a major version tag, if available. (trusted-tag-ref / warning)
with:
fetch-depth: 0

- name: Setup GitHub Token
id: setup-github-token
uses: smartcontractkit/.github/actions/setup-github-token@ef78fa97bf3c77de6563db1175422703e9e6674f # setup-github-token@0.2.1
uses: ./.github/actions/setup-github-token
with:
aws-role-arn: ${{ secrets.GATI_AWS_ROLE_ARN_CHAINLINK_READ_ONLY }}
aws-lambda-url: ${{ secrets.GATI_LAMBDA_URL_RELENG }}
aws-region: ${{ secrets.GATI_AWS_REGION }}
set-git-config: true

- name: Checkout code
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
fetch-depth: 0

- name: Set up Go
uses: actions/setup-go@v6 # v6
env:
Expand Down
13 changes: 7 additions & 6 deletions .github/workflows/repo-hygiene.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,20 +14,21 @@ jobs:
id-token: write
contents: read
steps:
# Local actions need the repo on disk, so checkout must precede setup-github-token.
- name: Checkout code
uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Setup GitHub Token
id: setup-github-token
uses: smartcontractkit/.github/actions/setup-github-token@ef78fa97bf3c77de6563db1175422703e9e6674f # setup-github-token@0.2.1
uses: ./.github/actions/setup-github-token
with:
aws-role-arn: ${{ secrets.GATI_AWS_ROLE_ARN_CHAINLINK_READ_ONLY }}
aws-lambda-url: ${{ secrets.GATI_LAMBDA_URL_RELENG }}
aws-region: ${{ secrets.GATI_AWS_REGION }}
set-git-config: true

- name: Checkout code
uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Set up Go
uses: actions/setup-go@v6 # v6
env:
Expand Down
Loading
Loading