feat(ci): support explicit runtime secret mapping #3

Merged
vadimenovikau merged 3 commits from codex/minio-runtime-secrets into main 2026-08-21 13:32:11 +00:00
Showing only changes of commit 1ab428b949 - Show all commits
@@ -6,6 +6,7 @@ import {
deployExactImage,
expandTokens,
mergeEnvironment,
resolveSecretEnvironment,
orderApplications,
resolveDeploymentBranch,
resolvePullRequestHeadBranch,
@@ -170,6 +171,24 @@ test("preserves response-only fields and existing environment secrets safely", (
assert.equal(mergeEnvironment(app().envVars, { ENVIRONMENT: "new" }), "SECRET=preserved\nENVIRONMENT=new");
});
test("maps only explicitly declared Actions secrets into runtime environment", () => {
assert.deepEqual(
resolveSecretEnvironment(
{ MINIO_ENDPOINT: "MINIO_ENDPOINT", MINIO_REGION: "MINIO_REGION" },
{ MINIO_ENDPOINT: "https://minio.example.test", MINIO_REGION: "us-east-1" },
),
{ MINIO_ENDPOINT: "https://minio.example.test", MINIO_REGION: "us-east-1" },
);
assert.throws(
() => resolveSecretEnvironment({ MINIO_ENDPOINT: "MINIO_ENDPOINT" }, {}),
/Missing Actions secret MINIO_ENDPOINT/,
);
assert.throws(
() => resolveSecretEnvironment({ "INVALID-KEY": "MINIO_ENDPOINT" }, { MINIO_ENDPOINT: "value" }),
/Invalid secret environment key/,
);
});
test("postflight waits for the exact expected identity", async () => {
let attempt = 0;
const result = await verifyEndpoint(