Skip to content

feat(gh-aw): mint OIDC ephemeral GitHub tokens in lock workflows - #1949

Merged
fr4nc1sc0-r4m0n merged 6 commits into
mainfrom
feat/mint-ephemeral-tokens-in-lock-workflows
Sep 1, 2026
Merged

fr4nc1sc0-r4m0n merged 6 commits into
mainfrom
feat/mint-ephemeral-tokens-in-lock-workflows

Conversation

@fr4nc1sc0-r4m0n

@fr4nc1sc0-r4m0n fr4nc1sc0-r4m0n commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add optional github-token-policy input to source workflows so lock workflows can mint short-lived GitHub installation tokens via elastic/oblt-actions/github/create-token when the input is non-empty.
  • Add a shared ephemeral-github-token workflow fragment and wire it into token-consuming lock workflows (issue-triage, dependency-review, and issue-fixer) so write operations prefer the minted token when policy is set.
  • Add scripts/wire-ephemeral-token.py with tests to rewrite compiled lock workflow token env expressions to prefer steps.create-token.outputs.token, and inject permissions.id-token: write only for jobs that mint tokens.
  • Keep default behavior unchanged for non-Elastic consumers: leave github-token-policy empty to continue using GITHUB_TOKEN / GH_AW_GITHUB_TOKEN.
  • Document that github-token-policy is Elastic-specific (TokenPolicy / ephemeral-token infrastructure) so common workflows do not become Elastic-only by default.

Merge order

Merge this PR first. The companion consumer change in elastic/oblt-aw passes github-token-policy to gh-aw-*.lock.yml@main and will fail until this lands.

  1. Merge this PR (elastic/ai-github-actions#1949).
  2. Then merge feat(workflows): enable in-lock ephemeral tokens on GH-AW callers oblt-aw#1762.

Companion: elastic/oblt-aw#1762

Validation

  • python3 -m pytest tests/test_wire_ephemeral_token.py -q (4 passed)
  • make compile

Risks / Known Gaps

  • Nested reusable OIDC workflow_ref should remain the consumer client trigger; if a run binds the lock file instead, catalog TokenPolicy may need an update.
  • Compiler SHA-pins create-token in lock files (gh-aw behavior); source fragment uses @v1.
  • Setting github-token-policy outside Elastic will not work without Elastic TokenPolicy / ephemeral-token infrastructure.

Why: GITHUB_TOKEN label and PR writes do not re-trigger other workflows.
What: Opt-in mint-ephemeral-token plus token-policy on issue-triage,
dependency-review, and issue-fixer; post-process lock files to prefer
create-token outputs.
Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q
@fr4nc1sc0-r4m0n fr4nc1sc0-r4m0n self-assigned this Aug 28, 2026
@github-actions github-actions Bot added the big_boom Large/high-risk PR blast radius; strong human review required label Aug 28, 2026
Why: Vault auto policy cannot match a shared wildcard TokenPolicy.
What: Drop create-token-auto; fail if mint-ephemeral-token is true without token-policy.
Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q; make compile
@github-actions github-actions Bot added medium_boom Medium PR blast radius; likely benefits from human review and removed big_boom Large/high-risk PR blast radius; strong human review required labels Aug 28, 2026
@fr4nc1sc0-r4m0n
fr4nc1sc0-r4m0n requested a review from v1v August 28, 2026 12:46
@github-actions github-actions Bot mentioned this pull request Aug 28, 2026
@fr4nc1sc0-r4m0n

Copy link
Copy Markdown
Contributor Author

Tested elastic/oblt-aw#1788

v1v

This comment was marked as resolved.

Why: mint-ephemeral-token was redundant once a shared TokenPolicy became required.
What: Drop the boolean; mint when github-token-policy is non-empty.
Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q; make compile
@fr4nc1sc0-r4m0n

Copy link
Copy Markdown
Contributor Author

what's the reason for using mint-ephemeral-token and token-policy? IIUC, if token-policy then mint-ephemeral-token should be true.

Can we just use token-policy instead? If so, can we rename the token-policy with github-token-policy so the name is explicit enough?

Yes, I agree. I was thinking to do that. Somehow I thought that using both was more descriptive, but using only one works well for me.

Done in 8e9dcc5

v1v

This comment was marked as resolved.

@fr4nc1sc0-r4m0n

Copy link
Copy Markdown
Contributor Author

One last comment, this is a specific Elastic configuration we are adding to the common workflows.

By doing so, it will imply they will become Elastic specifics.

See https://elastic.github.io/ai-github-actions/workflows/gh-agent-workflows/#elastic-specific-workflows

Wonder what's the action here?

Very good point @v1v. I envision basically two approaches here:

  1. Add the workflows which includes this new fragment to the elastic specifics' list
  2. Since this input is optional, add a clear warning in the docs about this new Elastic dependency if trying to provide the github-token-policy input.

WDYT? Do you have another way in mind?

@v1v

v1v commented Aug 31, 2026

Copy link
Copy Markdown
Member

WDYT?

Neat, that should help, thanks

Why: optional create-token minting must not imply common workflows are Elastic-only.
What: document the Elastic TokenPolicy dependency and leave default empty for non-Elastic.
Validation: make compile
@fr4nc1sc0-r4m0n

Copy link
Copy Markdown
Contributor Author

WDYT?

Neat, that should help, thanks

Thanks @v1v. Done here 233f79b

@fr4nc1sc0-r4m0n
fr4nc1sc0-r4m0n merged commit ce0eb7f into main Sep 1, 2026
27 checks passed
@fr4nc1sc0-r4m0n
fr4nc1sc0-r4m0n deleted the feat/mint-ephemeral-tokens-in-lock-workflows branch September 1, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

medium_boom Medium PR blast radius; likely benefits from human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants