Provision LOCALSTACK_AUTH_TOKEN for every repository

LocalStack is a common enough dependency that declaring it per repository is
busywork, and the token is already in the host environment when it is needed at
all. It is now provisioned host-wide, through the same custom-secret path as
the per-repository declarations, so the value stays out of the sandbox and the
proxy substitutes it on requests to localstack.cloud.

Provisioning is conditional on the sandbox having Docker. LocalStack runs as a
container, so on a sandbox created from a non-docker template the credential
would be dead weight, and the entry is skipped with a message rather than
stored. An unset variable is skipped silently, which costs nothing on a machine
that never uses LocalStack.

The provisioning body moves into provision_secret so the host-wide and
per-repository paths cannot drift apart.
This commit is contained in:
2026-07-31 12:09:56 -05:00
parent 93dc61a024
commit d2b7a5ef63
3 changed files with 116 additions and 36 deletions
+16
View File
@@ -69,6 +69,22 @@ REPOSITORY="other/repo"
[[ "$(secret_placeholder FONTAWESOME_API_KEY)" != "$first" ]] ||
fail "placeholder does not vary by repository"
for entry in "${HOST_WIDE_SECRETS[@]}"; do
IFS='|' read -r var hosts requirement <<<"$entry"
[[ -n "$var" ]] || fail "host-wide entry has no variable: $entry"
[[ -n "$hosts" ]] || fail "host-wide entry $var has no hosts"
[[ "$requirement" == docker || "$requirement" == "-" ]] ||
fail "host-wide entry $var has an unknown requirement: '$requirement'"
done
printf '%s\n' "${HOST_WIDE_SECRETS[@]}" | grep -q '^LOCALSTACK_AUTH_TOKEN|' ||
fail "LOCALSTACK_AUTH_TOKEN should be provisioned host-wide"
printf '%s\n' "${HOST_WIDE_SECRETS[@]}" | grep '^LOCALSTACK_AUTH_TOKEN|' |
grep -q 'localstack\.cloud' ||
fail "LOCALSTACK_AUTH_TOKEN must target localstack.cloud"
if ((failures)); then
printf '%d assertion(s) failed\n' "$failures" >&2
exit 1