Repository navigation
add gcp_audience input and pass it to the auth action warn when gcp_audience is set without a workload identity provider - #536
Open
rootkiller6788 wants to merge 2 commits into
Conversation
WIF setups that pin a custom audience on the provider currently can't work here, because we request the default audience (the provider resource name) when minting the OIDC token while the provider expects something else. The auth action already has an 'audience' input for this, so this just surfaces it. Leaving it unset keeps the old behaviour: auth falls back to the workload identity provider when the value is empty.
It's easy to drop 'gcp_audience' into a workflow that authenticates with an API key and then wonder why nothing changed - the audience only ends up in the OIDC token, so without WIF there is nothing to apply it to. Added it to the existing input checks next to the other WIF-specific ones.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #484.
Adds a
gcp_audienceinput and passes it through to the auth action'saudienceinput, which is what ends up in the OIDC token we hand to Workload Identity Federation. Right now we always request the provider resource name, so a provider configured to expect something else can't be used with this action at all.Leaving the input unset keeps today's behaviour: the auth action falls back to the workload identity provider when the value is empty, so this is purely opt-in.
I also added a check in the existing input validation step for the case where someone sets
gcp_audiencewithoutgcp_workload_identity_provider- it would silently do nothing otherwise, which is a confusing way to find out.Tested the validation script locally against a few input combinations (WIF + audience, audience without WIF, neither, no auth, three auth methods at once) and the existing warnings and the step's exit code are unchanged. I did not regenerate the README input table with
npm run docs- say the word if you want that in this PR.