feat: add support for gopass as a credential store #294
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: build | |
concurrency: | |
group: ${{ github.workflow }}-${{ github.ref }} | |
cancel-in-progress: true | |
on: | |
workflow_dispatch: | |
push: | |
branches: | |
- 'master' | |
tags: | |
- 'v*' | |
pull_request: | |
env: | |
DESTDIR: ./bin | |
GO_VERSION: 1.21.10 | |
jobs: | |
validate: | |
runs-on: ubuntu-22.04 | |
strategy: | |
fail-fast: false | |
matrix: | |
target: | |
- lint | |
- validate-vendor | |
steps: | |
- | |
name: Checkout | |
uses: actions/checkout@v4 | |
- | |
name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
- | |
name: Run | |
run: | | |
make ${{ matrix.target }} | |
test: | |
runs-on: ${{ matrix.os }} | |
strategy: | |
fail-fast: false | |
matrix: | |
os: | |
- ubuntu-22.04 | |
- ubuntu-20.04 | |
- macOS-14 | |
- macOS-13 | |
- windows-2022 | |
steps: | |
- | |
name: Checkout | |
uses: actions/checkout@v4 | |
- | |
name: Set up Go | |
uses: actions/setup-go@v5 | |
with: | |
go-version: ${{ env.GO_VERSION }} | |
- | |
name: Install deps (ubuntu) | |
if: startsWith(matrix.os, 'ubuntu-') | |
run: | | |
sudo apt-get update | |
sudo apt-get install -y dbus-x11 gnome-keyring libsecret-1-dev pass | |
- | |
name: Install deps (macOS) | |
if: startsWith(matrix.os, 'macOS-') | |
run: | | |
brew install pass | |
- | |
name: Install gopass | |
env: | |
GOPASS_VERSION: v1.15.5 | |
run: go install github.com/gopasspw/gopass@${{ env.GOPASS_VERSION }} | |
- | |
name: GPG conf | |
uses: actions/github-script@v7 | |
id: gpg | |
with: | |
script: | | |
const fs = require('fs'); | |
const sep = require('path').sep; | |
const gnupgfolder = `${require('os').homedir()}${sep}.gnupg`; | |
if (!fs.existsSync(gnupgfolder)){ | |
fs.mkdirSync(gnupgfolder); | |
} | |
fs.copyFile('.github/workflows/fixtures/gpg.conf', `${gnupgfolder}${sep}gpg.conf`, (err) => { | |
if (err) throw err; | |
}); | |
core.setOutput('key', fs.readFileSync('.github/workflows/fixtures/7D851EB72D73BDA0.key', {encoding: 'utf8'})); | |
core.setOutput('passphrase', fs.readFileSync('.github/workflows/fixtures/7D851EB72D73BDA0.pass', {encoding: 'utf8'})); | |
- | |
name: Import GPG key | |
uses: crazy-max/ghaction-import-gpg@v6 | |
with: | |
gpg_private_key: ${{ steps.gpg.outputs.key }} | |
passphrase: ${{ steps.gpg.outputs.passphrase }} | |
trust_level: 5 | |
- | |
name: Init pass | |
if: ${{ !startsWith(matrix.os, 'windows-') }} | |
run: | | |
pass init 7D851EB72D73BDA0 | |
shell: bash | |
- | |
name: Init gopass | |
run: | | |
gopass config mounts.path "${HOME}/.gopass-password-store" 1>/dev/null | |
gopass config core.autopush false 1>/dev/null | |
gopass config core.autosync false 1>/dev/null | |
gopass config core.exportkeys false 1>/dev/null | |
gopass config core.notifications false 1>/dev/null | |
gopass config core.color false 1>/dev/null | |
gopass config core.nopager true 1>/dev/null | |
gopass init --crypto gpgcli --storage fs 7D851EB72D73BDA0 | |
shell: bash | |
- | |
name: Test | |
run: | | |
make test COVERAGEDIR=${{ env.DESTDIR }} | |
shell: bash | |
- | |
name: Upload coverage | |
uses: codecov/codecov-action@v4 | |
if: github.repository == 'docker/docker-credential-helpers' | |
with: | |
file: ${{ env.DESTDIR }}/coverage.txt | |
token: ${{ secrets.CODECOV_TOKEN }} | |
test-sandboxed: | |
runs-on: ubuntu-22.04 | |
steps: | |
- | |
name: Checkout | |
uses: actions/checkout@v4 | |
- | |
name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
- | |
name: Test | |
uses: docker/bake-action@v4 | |
with: | |
targets: test | |
set: | | |
*.cache-from=type=gha,scope=test | |
*.cache-to=type=gha,scope=test,mode=max | |
- | |
name: Upload coverage | |
uses: codecov/codecov-action@v4 | |
if: github.repository == 'docker/docker-credential-helpers' | |
with: | |
file: ${{ env.DESTDIR }}//coverage.txt | |
token: ${{ secrets.CODECOV_TOKEN }} | |
build: | |
runs-on: ubuntu-22.04 | |
steps: | |
- | |
name: Checkout | |
uses: actions/checkout@v4 | |
with: | |
fetch-depth: 0 | |
- | |
name: Set up QEMU | |
uses: docker/setup-qemu-action@v3 | |
- | |
name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v3 | |
- | |
name: Build | |
run: | | |
make release | |
env: | |
CACHE_FROM: type=gha,scope=build | |
CACHE_TO: type=gha,scope=build,mode=max | |
- | |
name: List artifacts | |
run: | | |
tree -nh ${{ env.DESTDIR }} | |
- | |
name: Check artifacts | |
run: | | |
find ${{ env.DESTDIR }} -type f -exec file -e ascii -e text -- {} + | |
- | |
name: Upload artifacts | |
uses: actions/upload-artifact@v4 | |
with: | |
name: docker-credential-helpers | |
path: ${{ env.DESTDIR }}/* | |
if-no-files-found: error | |
- | |
name: GitHub Release | |
if: | | |
startsWith(github.ref, 'refs/tags/v') && | |
github.repository == 'docker/docker-credential-helpers' | |
uses: softprops/action-gh-release@69320dbe05506a9a39fc8ae11030b214ec2d1f87 # v2.0.5 | |
env: | |
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
with: | |
draft: true | |
files: ${{ env.DESTDIR }}/* | |
build-deb: | |
runs-on: ubuntu-22.04 | |
steps: | |
- | |
name: Checkout | |
uses: actions/checkout@v4 | |
with: | |
fetch-depth: 0 | |
- | |
name: Build | |
run: | | |
make deb |