Repository navigation
Migrate Toolkit CLI signing secrets #2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Migrate Toolkit CLI signing secrets | |
| on: | |
| workflow_dispatch: | |
| permissions: {} | |
| concurrency: | |
| group: migrate-toolkit-settings | |
| cancel-in-progress: false | |
| jobs: | |
| migrate: | |
| if: >- | |
| github.repository_id == '1114546946' && | |
| github.ref == 'refs/heads/main' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| environment: production | |
| env: | |
| GH_TOKEN: ${{ secrets.SENTRY_MCP_MIGRATION_PAT }} | |
| TARGET_REPOSITORY: getsentry/toolkit | |
| TARGET_REPOSITORY_ID: '957245447' | |
| APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }} | |
| APPLE_CERT_DATA: ${{ secrets.APPLE_CERT_DATA }} | |
| APPLE_CERT_PASSWORD: ${{ secrets.APPLE_CERT_PASSWORD }} | |
| APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} | |
| SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} | |
| steps: | |
| - name: Validate target and signing inputs | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| : "${GH_TOKEN:?SENTRY_MCP_MIGRATION_PAT is not configured}" | |
| : "${APPLE_API_KEY:?APPLE_API_KEY is not configured}" | |
| : "${APPLE_CERT_DATA:?APPLE_CERT_DATA is not configured}" | |
| : "${APPLE_CERT_PASSWORD:?APPLE_CERT_PASSWORD is not configured}" | |
| : "${APPLE_TEAM_ID:?APPLE_TEAM_ID is not configured}" | |
| : "${SENTRY_AUTH_TOKEN:?SENTRY_AUTH_TOKEN is not configured}" | |
| test "$(gh api "repos/${TARGET_REPOSITORY}" --jq .id)" = "${TARGET_REPOSITORY_ID}" | |
| test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release" --jq '.deployment_branch_policy | "\(.protected_branches):\(.custom_branch_policies)"')" = 'false:true' | |
| test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release/deployment-branch-policies" --jq '[.branch_policies[] | "\(.type):\(.name)"] | join(",")')" = 'branch:release/cli/*' | |
| - name: Copy CLI release signing secrets | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| set +x | |
| printf '%s' "${APPLE_API_KEY}" | gh secret set APPLE_API_KEY --repo "${TARGET_REPOSITORY}" --env cli-release --app actions | |
| printf '%s' "${APPLE_CERT_DATA}" | gh secret set APPLE_CERT_DATA --repo "${TARGET_REPOSITORY}" --env cli-release --app actions | |
| printf '%s' "${APPLE_CERT_PASSWORD}" | gh secret set APPLE_CERT_PASSWORD --repo "${TARGET_REPOSITORY}" --env cli-release --app actions | |
| printf '%s' "${APPLE_TEAM_ID}" | gh secret set APPLE_TEAM_ID --repo "${TARGET_REPOSITORY}" --env cli-release --app actions | |
| printf '%s' "${SENTRY_AUTH_TOKEN}" | gh secret set SENTRY_AUTH_TOKEN --repo "${TARGET_REPOSITORY}" --env cli-release --app actions | |
| - name: Verify CLI release signing secret names | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| test "$(gh api "repos/${TARGET_REPOSITORY}" --jq .id)" = "${TARGET_REPOSITORY_ID}" | |
| test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release" --jq '.deployment_branch_policy | "\(.protected_branches):\(.custom_branch_policies)"')" = 'false:true' | |
| test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release/deployment-branch-policies" --jq '[.branch_policies[] | "\(.type):\(.name)"] | join(",")')" = 'branch:release/cli/*' | |
| diff -u \ | |
| <(printf '%s\n' APPLE_API_KEY APPLE_CERT_DATA APPLE_CERT_PASSWORD APPLE_TEAM_ID SENTRY_AUTH_TOKEN | sort) \ | |
| <(gh secret list --repo "${TARGET_REPOSITORY}" --env cli-release --json name --jq '.[].name' | grep -E '^(APPLE_API_KEY|APPLE_CERT_DATA|APPLE_CERT_PASSWORD|APPLE_TEAM_ID|SENTRY_AUTH_TOKEN)$' | sort) |