feat(gh-aw): mint OIDC ephemeral GitHub tokens in lock workflows - #1949
Conversation
Why: GITHUB_TOKEN label and PR writes do not re-trigger other workflows. What: Opt-in mint-ephemeral-token plus token-policy on issue-triage, dependency-review, and issue-fixer; post-process lock files to prefer create-token outputs. Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q
Why: Vault auto policy cannot match a shared wildcard TokenPolicy. What: Drop create-token-auto; fail if mint-ephemeral-token is true without token-policy. Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q; make compile
|
Tested elastic/oblt-aw#1788 |
Why: mint-ephemeral-token was redundant once a shared TokenPolicy became required. What: Drop the boolean; mint when github-token-policy is non-empty. Validation: python3 -m pytest tests/test_wire_ephemeral_token.py -q; make compile
Yes, I agree. I was thinking to do that. Somehow I thought that using both was more descriptive, but using only one works well for me. Done in 8e9dcc5 |
Very good point @v1v. I envision basically two approaches here:
WDYT? Do you have another way in mind? |
Neat, that should help, thanks |
Why: optional create-token minting must not imply common workflows are Elastic-only. What: document the Elastic TokenPolicy dependency and leave default empty for non-Elastic. Validation: make compile
Summary
github-token-policyinput to source workflows so lock workflows can mint short-lived GitHub installation tokens viaelastic/oblt-actions/github/create-tokenwhen the input is non-empty.ephemeral-github-tokenworkflow fragment and wire it into token-consuming lock workflows (issue-triage,dependency-review, andissue-fixer) so write operations prefer the minted token when policy is set.scripts/wire-ephemeral-token.pywith tests to rewrite compiled lock workflow token env expressions to prefersteps.create-token.outputs.token, and injectpermissions.id-token: writeonly for jobs that mint tokens.github-token-policyempty to continue usingGITHUB_TOKEN/GH_AW_GITHUB_TOKEN.github-token-policyis Elastic-specific (TokenPolicy / ephemeral-token infrastructure) so common workflows do not become Elastic-only by default.Merge order
Merge this PR first. The companion consumer change in
elastic/oblt-awpassesgithub-token-policytogh-aw-*.lock.yml@mainand will fail until this lands.elastic/ai-github-actions#1949).Companion: elastic/oblt-aw#1762
Validation
python3 -m pytest tests/test_wire_ephemeral_token.py -q(4 passed)make compileRisks / Known Gaps
workflow_refshould remain the consumer client trigger; if a run binds the lock file instead, catalogTokenPolicymay need an update.create-tokenin lock files (gh-aw behavior); source fragment uses@v1.github-token-policyoutside Elastic will not work without Elastic TokenPolicy / ephemeral-token infrastructure.