Provision LOCALSTACK_AUTH_TOKEN for every repository
LocalStack is a common enough dependency that declaring it per repository is busywork, and the token is already in the host environment when it is needed at all. It is now provisioned host-wide, through the same custom-secret path as the per-repository declarations, so the value stays out of the sandbox and the proxy substitutes it on requests to localstack.cloud. Provisioning is conditional on the sandbox having Docker. LocalStack runs as a container, so on a sandbox created from a non-docker template the credential would be dead weight, and the entry is skipped with a message rather than stored. An unset variable is skipped silently, which costs nothing on a machine that never uses LocalStack. The provisioning body moves into provision_secret so the host-wide and per-repository paths cannot drift apart.
This commit is contained in:
@@ -69,6 +69,22 @@ REPOSITORY="other/repo"
|
||||
[[ "$(secret_placeholder FONTAWESOME_API_KEY)" != "$first" ]] ||
|
||||
fail "placeholder does not vary by repository"
|
||||
|
||||
for entry in "${HOST_WIDE_SECRETS[@]}"; do
|
||||
IFS='|' read -r var hosts requirement <<<"$entry"
|
||||
|
||||
[[ -n "$var" ]] || fail "host-wide entry has no variable: $entry"
|
||||
[[ -n "$hosts" ]] || fail "host-wide entry $var has no hosts"
|
||||
[[ "$requirement" == docker || "$requirement" == "-" ]] ||
|
||||
fail "host-wide entry $var has an unknown requirement: '$requirement'"
|
||||
done
|
||||
|
||||
printf '%s\n' "${HOST_WIDE_SECRETS[@]}" | grep -q '^LOCALSTACK_AUTH_TOKEN|' ||
|
||||
fail "LOCALSTACK_AUTH_TOKEN should be provisioned host-wide"
|
||||
|
||||
printf '%s\n' "${HOST_WIDE_SECRETS[@]}" | grep '^LOCALSTACK_AUTH_TOKEN|' |
|
||||
grep -q 'localstack\.cloud' ||
|
||||
fail "LOCALSTACK_AUTH_TOKEN must target localstack.cloud"
|
||||
|
||||
if ((failures)); then
|
||||
printf '%d assertion(s) failed\n' "$failures" >&2
|
||||
exit 1
|
||||
|
||||
Reference in New Issue
Block a user