6 ms·
GitHub Actions: Organization secrets
- some_furry 6y agoThis is really cool in a way that will make developers that use Github Actions one day ask, "How did we live without that?"
- yodon 6y agoYes - this looks like the thing that will get me to start using Github Actions
- nullwarp 6y agoI was asking for this exact thing on May 1st in slack. Glad it came through, I shelved the project until I could come up with something.
- justinwp 6y agoBy using a github action I wrote to sync secrets https://github.com/google/secrets-sync-action https://github.com/google/secrets-sync-action
- atarian 6y agoCould this replace Vault?
- rileymichael 6y agoIf your only use case for Vault is access to K/V secrets during a workflow (CD for example) -- then sure, it's a much simpler alternative. If you need access to secrets dynamically / at runtime (outside of the Actions container), or any of the other features Vault has, then no.
- izolate 6y agoI’m not sure if you’re aware but the GitHub API provides dynamic access to the secrets so you can theoretically use it in your application/outside your workflow.
- rileymichael 6y agodo you happen to have a link to the api docs for that? Everywhere I'm looking it doesn't return the value. https://developer.github.com/v3/actions/secrets/#get-a-repository-secret https://developer.github.com/v3/actions/secrets/#get-a-repos... and the blog states the same behavior I'm seeing in the docs: First, the API doesn’t return any values, only names. https://github.blog/2020-02-06-manage-secrets-and-more-with-the-github-actions-api/#managing-secrets https://github.blog/2020-02-06-manage-secrets-and-more-with-...
- izolate 6y agoNo, you're right, I was mistaken. Sorry about that.
- csomar 6y agoNot really. Vault offering is very extensive. Their product doesn't make much sense if all you were looking for was a simple deployment of your average amateur or small SaaS. Org and repositories secrets are simple security solutions for people who can't afford to use Vault.
- chucky_z 6y agoIt makes using org-level AppRoles with Vault really easy, but I wouldn't replace Vault with this. I use org contexts with CircleCI today to do this with a very generic AppRole that has access too 'secrets that should be in Vault, but are generally safe.' e.g.: a consul credential that can read/write from the terraform state area.
- DelightOne 6y agoDoes it come together with the actions feature to Github Enterprise?
- nodesocket 6y agoAwesome. Now we just need the ability for self hosted runners[1] to support multiple repos. As I understand it, currently you need to deploy a dedicated runner per repo. [1] https://help.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners https://help.github.com/en/actions/hosting-your-own-runners/...
- chrisrpatterson 6y agoself-hosted runners can be deployed for an org as well https://github.blog/changelog/2020-04-22-github-actions-organization-level-self-hosted-runners/ https://github.blog/changelog/2020-04-22-github-actions-orga....
- nodesocket 6y agoHuzzah! That’s great.
- ggordan 6y agoGreat to see. I've definitely missed it coming from circleci where you have contexts where you can define secrets that you can share across multiple repos
- kmf 6y agothis is a really awesome improvement - a bunch of my projects all deploy w/ actions using the same api token to cloudflare workers (using wrangler-action[1]), so this makes it super easy to add new projects or re-roll the key without having to go in and change each project's config. btw, if you're looking for an intro to github actions, i put out a video last december covering publishing your first github action workflow: https://youtu.be/J4EhgEskSZA https://youtu.be/J4EhgEskSZA [1]: https://github.com/cloudflare/wrangler-action https://github.com/cloudflare/wrangler-action
- hanniabu 6y agoNice vid!
- ignoramous 6y ago> ...a bunch of my projects all deploy w/ actions using the same api token to cloudflare workers... Assuming some of those are open source, would you please link to them?
- neximo64 6y agoCant you create a github action in a commit that simply spits the secret out? Anyone know how to prevent this hack? Is there a way to have an open repo except for the actions folder?
- jsmeaton 6y agoYou can prevent forks from running actions which guards against external parties. Nothing to be done about internal parties except policies.
- jopsen 6y agoI wish GitHub Actions had a mechanism for authenticating to third-party services without secrets. It could be as simple as calling a metadata API only available from inside a GitHub Actions container and obtain a oauth2 token/JWT for an external audience.
- captncraig 6y agoThis would be great. Then we could reliably use something like vault to store secrets with individual acls per-workflow, and have reasonable confidence that only that single workflow can access them.
- jopsen 6y agoI don't get the obsession with secrets... Why not give us some signed JWTs for external authentication. Secrets is only good for legacy systems.
- actionowl 6y agof i n a l l y ! This is very welcome, now how about organization-level branch protections please!