Fetch Docker secrets from AWS Secrets Manager #71
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow will build the project, run integration tests, and release. | |
| # Secret-backed jobs fetch credentials from AWS Secrets Manager using GitHub OIDC. | |
| name: Build, Check, Publish | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| branches: [ main ] | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| id-token: write | |
| contents: read | |
| steps: | |
| - name: Checkout Repo | |
| uses: actions/checkout@v3 | |
| - name: Configure AWS credentials for Docker Hub secrets (OIDC) | |
| if: github.event_name != 'pull_request' | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: arn:aws:iam::301904545275:role/oidc-github-hellosign-dropbox-sign-node-branch-main | |
| aws-region: us-west-2 | |
| - name: Get Docker Hub secrets from AWS Secrets Manager | |
| if: github.event_name != 'pull_request' | |
| uses: aws-actions/aws-secretsmanager-get-secrets@v3 | |
| with: | |
| secret-ids: | | |
| DOCKER_USERNAME,github-actions/hellosign/shared/docker-username | |
| DOCKER_TOKEN,github-actions/hellosign/shared/docker-token | |
| parse-json-secrets: false | |
| - name: Build SDK | |
| run: ./run-build | |
| - name: Ensure no changes in Generated Code | |
| run: ./bin/check-clean-git-status | |
| # This job runs on pull requests | |
| # Does not publish to npmjs.org, this is a dry-run only | |
| publish-test: | |
| runs-on: ubuntu-latest | |
| if: >- | |
| github.repository == 'hellosign/dropbox-sign-node' | |
| && github.ref != 'refs/heads/main' | |
| && github.event_name == 'pull_request' | |
| needs: [ build ] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v3 | |
| - uses: actions/setup-node@v3 | |
| with: | |
| node-version: '16.x' | |
| registry-url: 'https://registry.npmjs.org' | |
| - run: npm ci | |
| - run: npm publish --access=public --dry-run | |
| # This job runs on merging to "main" branch | |
| # Builds and publishes gem | |
| publish-prod: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| if: >- | |
| github.repository == 'hellosign/dropbox-sign-node' | |
| && github.ref == 'refs/heads/main' | |
| && github.event_name != 'pull_request' | |
| needs: [ build ] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v3 | |
| - name: Use Node.js 24 for trusted publishing | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '24.x' | |
| registry-url: 'https://registry.npmjs.org' | |
| - run: npm ci | |
| - name: Use npm with trusted publishing support | |
| run: npm install --global npm@11.19.1 | |
| - name: Publish package with trusted publishing | |
| run: npm publish --access=public | |
| # This job runs on merging to "main" branch | |
| # Creates a new tag using the value in the VERSION file | |
| cut-tag: | |
| runs-on: ubuntu-latest | |
| if: >- | |
| github.repository == 'hellosign/dropbox-sign-node' | |
| && github.ref == 'refs/heads/main' | |
| && github.event_name != 'pull_request' | |
| needs: [ publish-prod ] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v3 | |
| - name: Retrieve version | |
| run: echo "PACKAGE_VERSION=$(cat VERSION)" >> $GITHUB_ENV | |
| - name: Create tag | |
| uses: actions/github-script@v6 | |
| env: | |
| PACKAGE_VERSION: ${{ env.PACKAGE_VERSION }} | |
| with: | |
| script: | | |
| github.rest.git.createRef({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| ref: "refs/tags/" + process.env.PACKAGE_VERSION, | |
| sha: context.sha | |
| }) |