feat(ci): support explicit runtime secret mapping
Nuvisphere/Platform-CI: Immutable QuickStack OCI deployment / Build once and deploy exact digest (push) Canceled after 0s
Nuvisphere/Platform-CI: Immutable QuickStack OCI deployment / Build once and deploy exact digest (push) Canceled after 0s
This commit is contained in:
@@ -87,6 +87,33 @@ export function mergeEnvironment(source, overrides = {}) {
|
||||
return rows.map((row) => row.raw ?? `${row.key}=${row.value}`).join("\n");
|
||||
}
|
||||
|
||||
export function resolveSecretEnvironment(secretEnvironment = {}, environment = process.env) {
|
||||
if (
|
||||
secretEnvironment === null ||
|
||||
typeof secretEnvironment !== "object" ||
|
||||
Array.isArray(secretEnvironment)
|
||||
) {
|
||||
throw new Error("secretEnvironment must be an object.");
|
||||
}
|
||||
|
||||
const resolved = {};
|
||||
for (const [runtimeKey, rawSecretName] of Object.entries(secretEnvironment)) {
|
||||
if (!/^[A-Za-z_][A-Za-z0-9_]*$/.test(runtimeKey)) {
|
||||
throw new Error(`Invalid secret environment key ${runtimeKey}.`);
|
||||
}
|
||||
const secretName = String(rawSecretName);
|
||||
if (!/^[A-Za-z_][A-Za-z0-9_]*$/.test(secretName)) {
|
||||
throw new Error(`Invalid Actions secret name for ${runtimeKey}.`);
|
||||
}
|
||||
const value = environment[secretName];
|
||||
if (value === undefined || String(value).length === 0) {
|
||||
throw new Error(`Missing Actions secret ${secretName} for runtime environment ${runtimeKey}.`);
|
||||
}
|
||||
resolved[runtimeKey] = String(value);
|
||||
}
|
||||
return resolved;
|
||||
}
|
||||
|
||||
async function readBody(response) {
|
||||
const text = await response.text();
|
||||
if (!text) return null;
|
||||
@@ -605,9 +632,12 @@ function promoteArtifactAliases(artifacts, releaseTag, options) {
|
||||
async function deployApplications({ applications, artifacts, sha, client }) {
|
||||
for (const application of applications) {
|
||||
const artifact = artifacts.get(application.artifact);
|
||||
const environment = Object.fromEntries(
|
||||
const environment = {
|
||||
...Object.fromEntries(
|
||||
Object.entries(application.environment ?? {}).map(([key, value]) => [key, expandTokens(value, { sha })]),
|
||||
);
|
||||
),
|
||||
...resolveSecretEnvironment(application.secretEnvironment),
|
||||
};
|
||||
const result = await deployExactImage({
|
||||
client,
|
||||
appId: application.appId,
|
||||
|
||||
Reference in New Issue
Block a user