Skip to content

ci: use GitHub OIDC for Docker Hub auth in publish-agent - #121

Draft
mpailloncy wants to merge 1 commit into
docker:mainfrom
mpailloncy:oidc-hub-release
Draft

mpailloncy wants to merge 1 commit into
docker:mainfrom
mpailloncy:oidc-hub-release

Conversation

@mpailloncy

Copy link
Copy Markdown
Collaborator

🤖 Automated implementer agent — this comment was posted by the implementer bot from AI Factory, not by a human developer

Migrates publish-agent's Docker Hub authentication from a long-lived PAT to GitHub OIDC federation, per docker/gordon#753.

Changes

  • Added id-token: write to the job's permissions (kept contents: read).
  • Replaced the manual docker login --password-stdin step with docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0, configured for Docker Hub OIDC (username only, no password, DOCKERHUB_OIDC_CONNECTIONID env var — per login-action's documented OIDC support added in v4.5.0).
  • Removed all references to the long-lived HUB_OAT secret repo-wide (verified via grep).
  • Kept HUB_ORG (used as both the login username and the push namespace) — it is not a long-lived credential and stays in use.

Ticket corrections (verified against the actual workflow, not assumed)

  • The real secrets are HUB_ORG + HUB_OAT, not the ticket's HUB_USER/HUB_PAT. There is no separate namespace secret — HUB_ORG doubles as both username and namespace.
  • There is no "Upload README" step or /v2/users/login/ PAT token-exchange call anywhere in this repo, so that part of the ticket doesn't apply here — nothing to change.

Manual follow-ups (NOT included in this PR)

  • Docker Hub side: OIDC trust for repo:docker/docker-agent-action:ref:refs/heads/main must be configured in Docker Hub (assumed already done per the ticket).
  • Repo settings: a DOCKERHUB_OIDC_CONNECTIONID repository/organization variable must be added, holding the Hub-side OIDC connection ID — docker/login-action requires this env var for Hub OIDC and the workflow will fail without it. This was not mentioned in the original ticket.
  • Cleanup: delete the HUB_OAT GitHub secret and revoke the corresponding PAT on Docker Hub once this is merged and verified.

Opened as draft: the OIDC login mechanism itself is now fully confirmed against docker/login-action's v4.6.0 README, but this PR depends on the not-yet-provisioned DOCKERHUB_OIDC_CONNECTIONID variable above, so a human should confirm that follow-up before this goes live.

Validated with pnpm build + actionlint (clean, exit 0). Independently reviewed (approved, no findings).

Replace the manual docker login using the long-lived HUB_OAT PAT
with docker/login-action's Docker Hub OIDC support. Requires
id-token: write and a DOCKERHUB_OIDC_CONNECTIONID repo variable
pointing at the Hub-side OIDC connection.

Refs docker/gordon#753

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant