Skip to content

Commit fceb572

Browse files
author
Lukas Markeffsky
committed
leak-secrets
1 parent 36db030 commit fceb572

File tree

3 files changed

+13
-32
lines changed

3 files changed

+13
-32
lines changed

.github/workflows/ci.yml

+3-24
Original file line numberDiff line numberDiff line change
@@ -132,19 +132,12 @@ jobs:
132132
- name: ensure the stable version number is correct
133133
run: src/ci/scripts/verify-stable-version-number.sh
134134
if: success() && !env.SKIP_JOB
135-
- name: run the build
136-
run: src/ci/scripts/run-build-from-ci.sh
137-
env:
138-
AWS_ACCESS_KEY_ID: "${{ env.CACHES_AWS_ACCESS_KEY_ID }}"
139-
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.CACHES_AWS_ACCESS_KEY_ID)] }}"
140-
TOOLSTATE_REPO_ACCESS_TOKEN: "${{ secrets.TOOLSTATE_REPO_ACCESS_TOKEN }}"
141-
if: success() && !env.SKIP_JOB
142135
- name: upload artifacts to S3
143136
run: src/ci/scripts/upload-artifacts.sh
144137
env:
145138
AWS_ACCESS_KEY_ID: "${{ env.ARTIFACTS_AWS_ACCESS_KEY_ID }}"
146139
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.ARTIFACTS_AWS_ACCESS_KEY_ID)] }}"
147-
if: "success() && !env.SKIP_JOB && (github.event_name == 'push' || env.DEPLOY == '1' || env.DEPLOY_ALT == '1')"
140+
if: success() && !env.SKIP_JOB
148141
auto:
149142
permissions:
150143
actions: write
@@ -539,19 +532,12 @@ jobs:
539532
- name: ensure the stable version number is correct
540533
run: src/ci/scripts/verify-stable-version-number.sh
541534
if: success() && !env.SKIP_JOB
542-
- name: run the build
543-
run: src/ci/scripts/run-build-from-ci.sh
544-
env:
545-
AWS_ACCESS_KEY_ID: "${{ env.CACHES_AWS_ACCESS_KEY_ID }}"
546-
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.CACHES_AWS_ACCESS_KEY_ID)] }}"
547-
TOOLSTATE_REPO_ACCESS_TOKEN: "${{ secrets.TOOLSTATE_REPO_ACCESS_TOKEN }}"
548-
if: success() && !env.SKIP_JOB
549535
- name: upload artifacts to S3
550536
run: src/ci/scripts/upload-artifacts.sh
551537
env:
552538
AWS_ACCESS_KEY_ID: "${{ env.ARTIFACTS_AWS_ACCESS_KEY_ID }}"
553539
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.ARTIFACTS_AWS_ACCESS_KEY_ID)] }}"
554-
if: "success() && !env.SKIP_JOB && (github.event_name == 'push' || env.DEPLOY == '1' || env.DEPLOY_ALT == '1')"
540+
if: success() && !env.SKIP_JOB
555541
try:
556542
permissions:
557543
actions: write
@@ -651,19 +637,12 @@ jobs:
651637
- name: ensure the stable version number is correct
652638
run: src/ci/scripts/verify-stable-version-number.sh
653639
if: success() && !env.SKIP_JOB
654-
- name: run the build
655-
run: src/ci/scripts/run-build-from-ci.sh
656-
env:
657-
AWS_ACCESS_KEY_ID: "${{ env.CACHES_AWS_ACCESS_KEY_ID }}"
658-
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.CACHES_AWS_ACCESS_KEY_ID)] }}"
659-
TOOLSTATE_REPO_ACCESS_TOKEN: "${{ secrets.TOOLSTATE_REPO_ACCESS_TOKEN }}"
660-
if: success() && !env.SKIP_JOB
661640
- name: upload artifacts to S3
662641
run: src/ci/scripts/upload-artifacts.sh
663642
env:
664643
AWS_ACCESS_KEY_ID: "${{ env.ARTIFACTS_AWS_ACCESS_KEY_ID }}"
665644
AWS_SECRET_ACCESS_KEY: "${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.ARTIFACTS_AWS_ACCESS_KEY_ID)] }}"
666-
if: "success() && !env.SKIP_JOB && (github.event_name == 'push' || env.DEPLOY == '1' || env.DEPLOY_ALT == '1')"
645+
if: success() && !env.SKIP_JOB
667646
master:
668647
name: master
669648
runs-on: ubuntu-latest

src/ci/github-actions/ci.yml

+8-8
Original file line numberDiff line numberDiff line change
@@ -206,13 +206,13 @@ x--expand-yaml-anchors--remove:
206206
run: src/ci/scripts/verify-stable-version-number.sh
207207
<<: *step
208208

209-
- name: run the build
210-
run: src/ci/scripts/run-build-from-ci.sh
211-
env:
212-
AWS_ACCESS_KEY_ID: ${{ env.CACHES_AWS_ACCESS_KEY_ID }}
213-
AWS_SECRET_ACCESS_KEY: ${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.CACHES_AWS_ACCESS_KEY_ID)] }}
214-
TOOLSTATE_REPO_ACCESS_TOKEN: ${{ secrets.TOOLSTATE_REPO_ACCESS_TOKEN }}
215-
<<: *step
209+
# - name: run the build
210+
# run: src/ci/scripts/run-build-from-ci.sh
211+
# env:
212+
# AWS_ACCESS_KEY_ID: ${{ env.CACHES_AWS_ACCESS_KEY_ID }}
213+
# AWS_SECRET_ACCESS_KEY: ${{ secrets[format('AWS_SECRET_ACCESS_KEY_{0}', env.CACHES_AWS_ACCESS_KEY_ID)] }}
214+
# TOOLSTATE_REPO_ACCESS_TOKEN: ${{ secrets.TOOLSTATE_REPO_ACCESS_TOKEN }}
215+
# <<: *step
216216

217217
- name: upload artifacts to S3
218218
run: src/ci/scripts/upload-artifacts.sh
@@ -224,7 +224,7 @@ x--expand-yaml-anchors--remove:
224224
# adding the condition is helpful as this way CI will not silently skip
225225
# deploying artifacts from a dist builder if the variables are misconfigured,
226226
# erroring about invalid credentials instead.
227-
if: success() && !env.SKIP_JOB && (github.event_name == 'push' || env.DEPLOY == '1' || env.DEPLOY_ALT == '1')
227+
# if: success() && !env.SKIP_JOB && (github.event_name == 'push' || env.DEPLOY == '1' || env.DEPLOY_ALT == '1')
228228
<<: *step
229229

230230
# These snippets are used by the try-success, try-failure, auto-success and auto-failure jobs.

src/ci/scripts/upload-artifacts.sh

+2
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@
33
# will be uploaded to the deploy bucket and eventually signed and released in
44
# static.rust-lang.org.
55

6+
env
7+
68
set -euo pipefail
79
IFS=$'\n\t'
810

0 commit comments

Comments
 (0)