ci: use GitHub OIDC for Docker Hub auth in publish-agent - #121
Draft
mpailloncy wants to merge 1 commit into
Draft
mpailloncy wants to merge 1 commit into
mpailloncy wants to merge 1 commit into
Conversation
Replace the manual docker login using the long-lived HUB_OAT PAT with docker/login-action's Docker Hub OIDC support. Requires id-token: write and a DOCKERHUB_OIDC_CONNECTIONID repo variable pointing at the Hub-side OIDC connection. Refs docker/gordon#753
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Migrates
publish-agent's Docker Hub authentication from a long-lived PAT to GitHub OIDC federation, per docker/gordon#753.Changes
id-token: writeto the job'spermissions(keptcontents: read).docker login --password-stdinstep withdocker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0, configured for Docker Hub OIDC (usernameonly, nopassword,DOCKERHUB_OIDC_CONNECTIONIDenv var — per login-action's documented OIDC support added in v4.5.0).HUB_OATsecret repo-wide (verified via grep).HUB_ORG(used as both the login username and the push namespace) — it is not a long-lived credential and stays in use.Ticket corrections (verified against the actual workflow, not assumed)
HUB_ORG+HUB_OAT, not the ticket'sHUB_USER/HUB_PAT. There is no separate namespace secret —HUB_ORGdoubles as both username and namespace./v2/users/login/PAT token-exchange call anywhere in this repo, so that part of the ticket doesn't apply here — nothing to change.Manual follow-ups (NOT included in this PR)
repo:docker/docker-agent-action:ref:refs/heads/mainmust be configured in Docker Hub (assumed already done per the ticket).DOCKERHUB_OIDC_CONNECTIONIDrepository/organization variable must be added, holding the Hub-side OIDC connection ID —docker/login-actionrequires this env var for Hub OIDC and the workflow will fail without it. This was not mentioned in the original ticket.HUB_OATGitHub secret and revoke the corresponding PAT on Docker Hub once this is merged and verified.Opened as draft: the OIDC login mechanism itself is now fully confirmed against
docker/login-action's v4.6.0 README, but this PR depends on the not-yet-provisionedDOCKERHUB_OIDC_CONNECTIONIDvariable above, so a human should confirm that follow-up before this goes live.Validated with
pnpm build+actionlint(clean, exit 0). Independently reviewed (approved, no findings).