Forward GITHUB_TOKEN into Linux Dagger containers for API auth

Add env: GITHUB_TOKEN to the Linux workflow step, then read it in
ci/main.go and inject it into each test container via WithSecretVariable
(for both GITHUB_TOKEN and GH_TOKEN). This prevents 403 rate-limit
errors on GitHub API calls (neovim/nvm releases) and authenticates
gh CLI for gh extension install inside the containers.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
2026-05-26 13:37:48 -05:00
co-authored by Copilot
parent a2f36665a3
commit c3ddcb336a
2 changed files with 10 additions and 0 deletions
+2
View File
@@ -29,6 +29,8 @@ jobs:
go-version: '1.25.x' go-version: '1.25.x'
- name: Run Dagger Integration Pipeline - name: Run Dagger Integration Pipeline
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: | run: |
go run ci/main.go --os ${{ matrix.os }} go run ci/main.go --os ${{ matrix.os }}
+8
View File
@@ -88,6 +88,14 @@ func main() {
WithFile("/usr/local/bin/bootstrap_environment", binaryFile). WithFile("/usr/local/bin/bootstrap_environment", binaryFile).
WithWorkdir("/tmp") WithWorkdir("/tmp")
// Forward GitHub token so API calls are authenticated (avoids 403 rate-limits)
if tok := os.Getenv("GITHUB_TOKEN"); tok != "" {
secret := client.SetSecret("github-token", tok)
testContainer = testContainer.
WithSecretVariable("GITHUB_TOKEN", secret).
WithSecretVariable("GH_TOKEN", secret)
}
// 4. Run bootstrap binary with safe args: --only custom --no-vm --no-ai // 4. Run bootstrap binary with safe args: --only custom --no-vm --no-ai
// We pipe 'y' to satisfy the "Proceed? [y/N]" prompt. // We pipe 'y' to satisfy the "Proceed? [y/N]" prompt.
fmt.Printf("[%s] Executing bootstrap_environment...\n", target) fmt.Printf("[%s] Executing bootstrap_environment...\n", target)