Skip to content

Fetch Docker secrets from AWS Secrets Manager #71

Fetch Docker secrets from AWS Secrets Manager

Fetch Docker secrets from AWS Secrets Manager #71

# This workflow will build the project, run integration tests, and release.
# Secret-backed jobs fetch credentials from AWS Secrets Manager using GitHub OIDC.
name: Build, Check, Publish
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- name: Checkout Repo
uses: actions/checkout@v3
- name: Configure AWS credentials for Docker Hub secrets (OIDC)
if: github.event_name != 'pull_request'
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::301904545275:role/oidc-github-hellosign-dropbox-sign-node-branch-main
aws-region: us-west-2
- name: Get Docker Hub secrets from AWS Secrets Manager
if: github.event_name != 'pull_request'
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
DOCKER_USERNAME,github-actions/hellosign/shared/docker-username
DOCKER_TOKEN,github-actions/hellosign/shared/docker-token
parse-json-secrets: false
- name: Build SDK
run: ./run-build
- name: Ensure no changes in Generated Code
run: ./bin/check-clean-git-status
# This job runs on pull requests
# Does not publish to npmjs.org, this is a dry-run only
publish-test:
runs-on: ubuntu-latest
if: >-
github.repository == 'hellosign/dropbox-sign-node'
&& github.ref != 'refs/heads/main'
&& github.event_name == 'pull_request'
needs: [ build ]
steps:
- name: Checkout
uses: actions/checkout@v3
- uses: actions/setup-node@v3
with:
node-version: '16.x'
registry-url: 'https://registry.npmjs.org'
- run: npm ci
- run: npm publish --access=public --dry-run
# This job runs on merging to "main" branch
# Builds and publishes gem
publish-prod:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
if: >-
github.repository == 'hellosign/dropbox-sign-node'
&& github.ref == 'refs/heads/main'
&& github.event_name != 'pull_request'
needs: [ build ]
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Use Node.js 24 for trusted publishing
uses: actions/setup-node@v4
with:
node-version: '24.x'
registry-url: 'https://registry.npmjs.org'
- run: npm ci
- name: Use npm with trusted publishing support
run: npm install --global npm@11.19.1
- name: Publish package with trusted publishing
run: npm publish --access=public
# This job runs on merging to "main" branch
# Creates a new tag using the value in the VERSION file
cut-tag:
runs-on: ubuntu-latest
if: >-
github.repository == 'hellosign/dropbox-sign-node'
&& github.ref == 'refs/heads/main'
&& github.event_name != 'pull_request'
needs: [ publish-prod ]
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Retrieve version
run: echo "PACKAGE_VERSION=$(cat VERSION)" >> $GITHUB_ENV
- name: Create tag
uses: actions/github-script@v6
env:
PACKAGE_VERSION: ${{ env.PACKAGE_VERSION }}
with:
script: |
github.rest.git.createRef({
owner: context.repo.owner,
repo: context.repo.repo,
ref: "refs/tags/" + process.env.PACKAGE_VERSION,
sha: context.sha
})