Skip to content

Add ImportSecretsAs to import GitHub Actions secrets under an explicit env name - #698

Draft
ChrisonSimtian wants to merge 3 commits into
Fallout-build:developfrom
ChrisonSimtian:hotfix/v10.4.1-import-secrets-as
Draft

ChrisonSimtian wants to merge 3 commits into
Fallout-build:developfrom
ChrisonSimtian:hotfix/v10.4.1-import-secrets-as

Conversation

@ChrisonSimtian

@ChrisonSimtian ChrisonSimtian commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

ImportSecrets derives the secret name from the parameter name. It cannot import a secret like OPS_API_TESTS_NZPOST_KEY (derivation gives NZ_POST). It also cannot set env names such as Apis__NzPost__FunctionKey. Consumers work around this by overriding the protected GetImports() in a subclass.

Outcome

  • New GitHubActionsAttribute.ImportSecretsAs property. Entries are ENV_NAME: SECRET_NAME.
  • Emitted on the run step's env: as ENV_NAME: ${{ secrets.SECRET_NAME }}, after ImportSecrets.
  • Secrets stay on the run step only.
  • Empty property: generated output is unchanged.
  • Validation, in the same style as Env:
    • env name and secret name must be non-empty
    • no whitespace in either
    • no duplicate env names across ImportSecrets and ImportSecretsAs

Notes

  • Additive, non-breaking. Targets develop.
  • Backport to the 10.4.x line after merge, if it should ship as a patch.
  • Docs: new section in docs/website/05-cicd/github-actions.md.

Tests

  • Two snapshot specs: ImportSecrets alone, and both properties together.
  • GitHubActionsImportSecretsAsSpecs: malformed entries, duplicates, same secret under two env names.
  • GitHubActions and ConfigurationGeneration specs pass.

@ChrisonSimtian ChrisonSimtian added enhancement New feature or request target/vCurrent Targets the current version labels Oct 5, 2026
ChrisonSimtian and others added 3 commits October 5, 2026 13:58
…t env name

ImportSecrets derives the secret name from the parameter name, so it cannot
reach secrets such as OPS_API_TESTS_NZPOST_KEY or env names such as
Apis__NzPost__FunctionKey. ImportSecretsAs takes "ENV_NAME: SECRET_NAME"
entries and emits them on the run step's env block after ImportSecrets.

Entries are validated like Env: non-empty env name and secret, no whitespace,
and no duplicate env names across both properties. Output is unchanged when
the property is empty.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… token is enabled

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@ChrisonSimtian
ChrisonSimtian force-pushed the hotfix/v10.4.1-import-secrets-as branch from 0910b02 to 336cb69 Compare October 5, 2026 00:59
@ChrisonSimtian
ChrisonSimtian changed the base branch from main to develop October 5, 2026 00:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request target/vCurrent Targets the current version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant