adding PAT authentication approach for clone

This commit is contained in:
2025-08-25 18:54:13 -05:00
committed by Jason Ross
parent 22eecc238e
commit 0355091094
+18 -14
View File
@@ -20,6 +20,8 @@ env:
FPM_VERSION: "1.16.0"
# SSH private key for GitHub operations (populate in repository secrets)
CI_CD_GH_SSH_KEY: ${{ secrets.CI_CD_GH_SSH_KEY }}
# Personal Access Token for HTTPS git operations (populate in repository secrets)
CI_CD_PAT: ${{ secrets.CI_CD_PAT }}
jobs:
build-windows:
@@ -246,23 +248,25 @@ jobs:
echo "Cloning pyenv (${PYENV_PYENV_REF}) and python-build (${PYENV_BUILD_REF}) via git (shallow)"
# Prefer SSH clones so CI can authenticate using a private key
REPO_PYENV="git@github.com:pyenv/pyenv.git"
REPO_BUILD="git@github.com:pyenv/pyenv-build.git"
# Use HTTPS clones and a repository PAT when available
REPO_PYENV="https://github.com/pyenv/pyenv.git"
REPO_BUILD="https://github.com/pyenv/pyenv-build.git"
# If a CI SSH key is provided, configure SSH for git operations
if [ -n "${CI_CD_GH_SSH_KEY:-}" ]; then
echo "Configuring SSH for GitHub using CI_CD_GH_SSH_KEY"
mkdir -p ~/.ssh
# write key and restrict permissions
printf '%s' "${CI_CD_GH_SSH_KEY}" > ~/.ssh/ci_cd_afh_adb
chmod 600 ~/.ssh/ci_cd_afh_adb
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/ci_cd_afh_adb
# ensure GitHub's host key is known to avoid interactive prompt
ssh-keyscan github.com >> ~/.ssh/known_hosts
EXTRA_HEADER=""
if [ -n "${CI_CD_PAT:-}" ]; then
echo "Configuring git to use CI_CD_PAT for HTTPS operations"
# Create Authorization header: Basic base64(:PAT)
EXTRA_HEADER="AUTHORIZATION: basic $(printf ':%s' "${CI_CD_PAT}" | base64)"
fi
gitx() {
if [ -n "${EXTRA_HEADER}" ]; then
git -c http.extraHeader="${EXTRA_HEADER}" "$@"
else
git "$@"
fi
}
# pyenv: shallow clone the requested ref if possible, otherwise fall back to default shallow clone
if [ -d "$PYENV_ROOT/.git" ]; then
retry git -C "$PYENV_ROOT" fetch --all --prune --depth=1 || true