Skip to content

Grant a deploy credential to a component-name pattern #3090

Description

@dawsontoth

Problem

Deploy credentials for private sources are secret rows named deploy.<component>.<host> and granted to exact component names: components/componentSecrets.ts:342, :555 and :734 check row.grants.includes(componentName).

A PR preview is a new component for every PR. So the recipe in HarperFast/documentation#715 has an administrator do all of this by hand:

  • Run harper deploy setup=true provider=github project=my-app-pr-42 before each PR's preview can deploy from a private repository. The first run of every PR fails until that's done.
  • Rotate each active preview's own row when the token changes.
  • delete_secret each row after cleanup, because dropping the component leaves it behind.

Private registry builds have the same per-project step.

Proposal

  • Allow a deploy-credential grant to a component-name pattern, e.g. my-app-pr-*, so one dedicated, read-only preview token covers every preview of that app.
  • Use the same pattern rules as the component-scoped deploy grant (Scope deploy permissions to component names #3046).
  • Grants stay exact for everything else.
  • Keep the production token out of it. Preview code can read secrets granted to its component.

Done when

  • my-app-pr-42 deploys from a private repository with a credential granted to my-app-pr-*, with no per-PR setup.
  • Dropping it leaves nothing to delete.
  • my-app doesn't match the pattern.

Part of #3042.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Fields

    Priority

    P2

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions