feat(onboarding): artifact ingest + classifier + suite-integration seams #138
+14
-10
@@ -50,19 +50,23 @@ jobs:
|
|||||||
RUSTC_WRAPPER: ""
|
RUSTC_WRAPPER: ""
|
||||||
|
|
||||||
# compliance-agent has a git dependency on tramiton-core (a private repo on
|
# compliance-agent has a git dependency on tramiton-core (a private repo on
|
||||||
# this Gitea instance). Rewrite its SSH URL to HTTPS and authenticate with
|
# this Gitea instance). The ephemeral Actions token can NOT clone it even
|
||||||
# the ephemeral Actions token using the same Basic-auth extraheader form
|
# with a Collaborative Owner grant (that only covers `uses:` actions), and
|
||||||
# that actions/checkout uses (username `x-access-token`) — no PAT needed,
|
# Gitea PATs can't be scoped to a single repo. So use a read-only Deploy
|
||||||
# provided sharang/tramiton grants this repo access via Collaborative Owners
|
# Key (per-repo): add the public key to sharang/tramiton → Settings →
|
||||||
# (tramiton → Settings → Actions).
|
# Deploy Keys (read-only), and the matching private key as this repo's
|
||||||
- name: Configure git auth for private tramiton dependency
|
# TRAMITON_DEPLOY_KEY secret. cargo fetches the dep over SSH using it.
|
||||||
|
- name: Configure SSH deploy key for private tramiton dependency
|
||||||
env:
|
env:
|
||||||
GITEA_ACTIONS_TOKEN: ${{ github.token }}
|
TRAMITON_DEPLOY_KEY: ${{ secrets.TRAMITON_DEPLOY_KEY }}
|
||||||
RUSTC_WRAPPER: ""
|
RUSTC_WRAPPER: ""
|
||||||
run: |
|
run: |
|
||||||
AUTH=$(printf 'x-access-token:%s' "$GITEA_ACTIONS_TOKEN" | base64 -w0)
|
apt-get update && apt-get install -y --no-install-recommends openssh-client
|
||||||
git config --global http."https://gitea.meghsakha.com/".extraheader "Authorization: Basic $AUTH"
|
mkdir -p ~/.ssh && chmod 700 ~/.ssh
|
||||||
git config --global url."https://gitea.meghsakha.com/".insteadOf "ssh://git@gitea.meghsakha.com:22222/"
|
printf '%s\n' "$TRAMITON_DEPLOY_KEY" > ~/.ssh/tramiton_ci
|
||||||
|
chmod 600 ~/.ssh/tramiton_ci
|
||||||
|
printf 'Host gitea.meghsakha.com\n HostName gitea.meghsakha.com\n Port 22222\n User git\n IdentityFile ~/.ssh/tramiton_ci\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' > ~/.ssh/config
|
||||||
|
chmod 600 ~/.ssh/config
|
||||||
|
|
||||||
# Format (no compilation needed)
|
# Format (no compilation needed)
|
||||||
- name: Format
|
- name: Format
|
||||||
|
|||||||
Reference in New Issue
Block a user