Skip to content

Migrate Toolkit CLI signing secrets #2

Migrate Toolkit CLI signing secrets

Migrate Toolkit CLI signing secrets #2

name: Migrate Toolkit CLI signing secrets
on:
workflow_dispatch:
permissions: {}
concurrency:
group: migrate-toolkit-settings
cancel-in-progress: false
jobs:
migrate:
if: >-
github.repository_id == '1114546946' &&
github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
timeout-minutes: 10
environment: production
env:
GH_TOKEN: ${{ secrets.SENTRY_MCP_MIGRATION_PAT }}
TARGET_REPOSITORY: getsentry/toolkit
TARGET_REPOSITORY_ID: '957245447'
APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }}
APPLE_CERT_DATA: ${{ secrets.APPLE_CERT_DATA }}
APPLE_CERT_PASSWORD: ${{ secrets.APPLE_CERT_PASSWORD }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
steps:
- name: Validate target and signing inputs
shell: bash
run: |
set -euo pipefail
: "${GH_TOKEN:?SENTRY_MCP_MIGRATION_PAT is not configured}"
: "${APPLE_API_KEY:?APPLE_API_KEY is not configured}"
: "${APPLE_CERT_DATA:?APPLE_CERT_DATA is not configured}"
: "${APPLE_CERT_PASSWORD:?APPLE_CERT_PASSWORD is not configured}"
: "${APPLE_TEAM_ID:?APPLE_TEAM_ID is not configured}"
: "${SENTRY_AUTH_TOKEN:?SENTRY_AUTH_TOKEN is not configured}"
test "$(gh api "repos/${TARGET_REPOSITORY}" --jq .id)" = "${TARGET_REPOSITORY_ID}"
test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release" --jq '.deployment_branch_policy | "\(.protected_branches):\(.custom_branch_policies)"')" = 'false:true'
test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release/deployment-branch-policies" --jq '[.branch_policies[] | "\(.type):\(.name)"] | join(",")')" = 'branch:release/cli/*'
- name: Copy CLI release signing secrets
shell: bash
run: |
set -euo pipefail
set +x
printf '%s' "${APPLE_API_KEY}" | gh secret set APPLE_API_KEY --repo "${TARGET_REPOSITORY}" --env cli-release --app actions
printf '%s' "${APPLE_CERT_DATA}" | gh secret set APPLE_CERT_DATA --repo "${TARGET_REPOSITORY}" --env cli-release --app actions
printf '%s' "${APPLE_CERT_PASSWORD}" | gh secret set APPLE_CERT_PASSWORD --repo "${TARGET_REPOSITORY}" --env cli-release --app actions
printf '%s' "${APPLE_TEAM_ID}" | gh secret set APPLE_TEAM_ID --repo "${TARGET_REPOSITORY}" --env cli-release --app actions
printf '%s' "${SENTRY_AUTH_TOKEN}" | gh secret set SENTRY_AUTH_TOKEN --repo "${TARGET_REPOSITORY}" --env cli-release --app actions
- name: Verify CLI release signing secret names
shell: bash
run: |
set -euo pipefail
test "$(gh api "repos/${TARGET_REPOSITORY}" --jq .id)" = "${TARGET_REPOSITORY_ID}"
test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release" --jq '.deployment_branch_policy | "\(.protected_branches):\(.custom_branch_policies)"')" = 'false:true'
test "$(gh api "repos/${TARGET_REPOSITORY}/environments/cli-release/deployment-branch-policies" --jq '[.branch_policies[] | "\(.type):\(.name)"] | join(",")')" = 'branch:release/cli/*'
diff -u \
<(printf '%s\n' APPLE_API_KEY APPLE_CERT_DATA APPLE_CERT_PASSWORD APPLE_TEAM_ID SENTRY_AUTH_TOKEN | sort) \
<(gh secret list --repo "${TARGET_REPOSITORY}" --env cli-release --json name --jq '.[].name' | grep -E '^(APPLE_API_KEY|APPLE_CERT_DATA|APPLE_CERT_PASSWORD|APPLE_TEAM_ID|SENTRY_AUTH_TOKEN)$' | sort)