adding PAT authentication approach for clone
This commit is contained in:
@@ -20,6 +20,8 @@ env:
|
||||
FPM_VERSION: "1.16.0"
|
||||
# SSH private key for GitHub operations (populate in repository secrets)
|
||||
CI_CD_GH_SSH_KEY: ${{ secrets.CI_CD_GH_SSH_KEY }}
|
||||
# Personal Access Token for HTTPS git operations (populate in repository secrets)
|
||||
CI_CD_PAT: ${{ secrets.CI_CD_PAT }}
|
||||
|
||||
jobs:
|
||||
build-windows:
|
||||
@@ -246,23 +248,25 @@ jobs:
|
||||
|
||||
echo "Cloning pyenv (${PYENV_PYENV_REF}) and python-build (${PYENV_BUILD_REF}) via git (shallow)"
|
||||
|
||||
# Prefer SSH clones so CI can authenticate using a private key
|
||||
REPO_PYENV="git@github.com:pyenv/pyenv.git"
|
||||
REPO_BUILD="git@github.com:pyenv/pyenv-build.git"
|
||||
# Use HTTPS clones and a repository PAT when available
|
||||
REPO_PYENV="https://github.com/pyenv/pyenv.git"
|
||||
REPO_BUILD="https://github.com/pyenv/pyenv-build.git"
|
||||
|
||||
# If a CI SSH key is provided, configure SSH for git operations
|
||||
if [ -n "${CI_CD_GH_SSH_KEY:-}" ]; then
|
||||
echo "Configuring SSH for GitHub using CI_CD_GH_SSH_KEY"
|
||||
mkdir -p ~/.ssh
|
||||
# write key and restrict permissions
|
||||
printf '%s' "${CI_CD_GH_SSH_KEY}" > ~/.ssh/ci_cd_afh_adb
|
||||
chmod 600 ~/.ssh/ci_cd_afh_adb
|
||||
eval "$(ssh-agent -s)"
|
||||
ssh-add ~/.ssh/ci_cd_afh_adb
|
||||
# ensure GitHub's host key is known to avoid interactive prompt
|
||||
ssh-keyscan github.com >> ~/.ssh/known_hosts
|
||||
EXTRA_HEADER=""
|
||||
if [ -n "${CI_CD_PAT:-}" ]; then
|
||||
echo "Configuring git to use CI_CD_PAT for HTTPS operations"
|
||||
# Create Authorization header: Basic base64(:PAT)
|
||||
EXTRA_HEADER="AUTHORIZATION: basic $(printf ':%s' "${CI_CD_PAT}" | base64)"
|
||||
fi
|
||||
|
||||
gitx() {
|
||||
if [ -n "${EXTRA_HEADER}" ]; then
|
||||
git -c http.extraHeader="${EXTRA_HEADER}" "$@"
|
||||
else
|
||||
git "$@"
|
||||
fi
|
||||
}
|
||||
|
||||
# pyenv: shallow clone the requested ref if possible, otherwise fall back to default shallow clone
|
||||
if [ -d "$PYENV_ROOT/.git" ]; then
|
||||
retry git -C "$PYENV_ROOT" fetch --all --prune --depth=1 || true
|
||||
|
||||
Reference in New Issue
Block a user