Skip to content

Commit 8260600

Browse files
kranthi0003CopilotCopilotsophietheking
authored
Clarify how environment secrets work in reusable workflows (#63727)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Sophie <29382425+sophietheking@users.noreply.github.com> Copilot-Session: b729a193-1aea-40ef-97c7-b4e495668513 Copilot-Session: f6f8a5df-86a8-44d1-89ec-f8fc70f637ae
1 parent ae3a5bf commit 8260600

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

‎content/actions/how-tos/reuse-automations/reuse-workflows.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,8 +72,14 @@ You can define inputs and secrets, which can be passed from the caller workflow
7272

7373
In the example above, `personal_access_token` is a secret that's defined at the repository or organization level.
7474

75+
To use an environment secret in a reusable workflow, set `environment` on the job in the reusable workflow. The job that calls the reusable workflow can't use the `environment` keyword. For more information, see [AUTOTITLE](/actions/how-tos/deploy/configure-and-manage-deployments/manage-environments).
76+
77+
The caller workflow must still pass the secret. Use `secrets: inherit` or pass the secret by name, for example {% raw %}`MY_SECRET: ${{ secrets.MY_SECRET }}`{% endraw %}. You can pass a secret by name even if it only exists in the environment.
78+
79+
If an environment secret has the same name as a repository or organization secret, the environment secret takes precedence. This applies when the caller uses either `secrets: inherit` or {% raw %}`${{ secrets.MY_SECRET }}`{% endraw %}. The job that sets `environment` receives the environment secret's value.
80+
7581
> [!WARNING]
76-
> Environment secrets cannot be passed from the caller workflow as `on.workflow_call` does not support the `environment` keyword. If you include `environment` in the reusable workflow at the job level, the environment secret will be used, and not the secret passed from the caller workflow. For more information, see [AUTOTITLE](/actions/how-tos/deploy/configure-and-manage-deployments/manage-environments) and [AUTOTITLE](/actions/reference/workflows-and-actions/workflow-syntax#onworkflow_call).
82+
> If the caller workflow doesn't pass an environment secret, the secret resolves to an empty string in the reusable workflow. The workflow run doesn't show an error. To make the workflow run fail instead, set `required: true` for the secret in [`on.workflow_call.secrets`](/actions/reference/workflows-and-actions/workflow-syntax#onworkflow_callsecrets). This setting only checks whether the caller workflow passes the secret. It doesn't check whether the secret has a value.
7783

7884
1. Pass the input or secret from the caller workflow.
7985

0 commit comments

Comments
 (0)