Skip to content

Commit 19e9d47

Browse files
Update GitHub Actions workflow for agent build
1 parent 2d27c74 commit 19e9d47

1 file changed

Lines changed: 32 additions & 20 deletions

File tree

.github/workflows/agent-build.yml

Lines changed: 32 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,37 +1,52 @@
1-
name: 'Agent Zip Build'
1+
name: Agent Zip Build
22
on:
33
workflow_dispatch:
44
inputs:
55
buildType:
66
type: choice
7-
description: 'Build Type'
7+
description: "Build Type"
88
required: true
9-
options:
9+
options:
1010
- Testing
1111
- Release
1212
buildVersion:
13-
description: 'Build Version'
13+
description: "Build Version"
1414
required: true
15+
16+
permissions:
17+
id-token: write
18+
contents: write
19+
1520
jobs:
1621
Build:
1722
runs-on: ubuntu-latest
1823
steps:
1924
- uses: actions/checkout@v3
20-
- uses: actions/setup-java@v3
25+
26+
- uses: actions/setup-java@v4
2127
with:
22-
distribution: 'zulu'
23-
java-version: '11'
28+
distribution: "zulu"
29+
java-version: "11"
30+
31+
- name: Set AWS environment
32+
run: |
33+
echo "AWS_DEFAULT_REGION=us-east-1" >> $GITHUB_ENV
34+
echo "AWS_DEFAULT_OUTPUT=json" >> $GITHUB_ENV
35+
echo "AWS_ROLE_ARN=${{ secrets.STAGE_AWS_GITHUB_OIDC_ROLE_ARN }}" >> $GITHUB_ENV
36+
37+
- name: Configure AWS credentials (OIDC)
38+
uses: aws-actions/configure-aws-credentials@v4
39+
with:
40+
role-to-assume: ${{ env.AWS_ROLE_ARN }}
41+
role-session-name: GitHub_to_AWS_via_FederatedOIDC
42+
aws-region: ${{ env.AWS_DEFAULT_REGION }}
43+
2444
- name: Downloading Packages
2545
run: |
26-
mkdir $HOME/.testsigma_os
46+
mkdir -p $HOME/.testsigma_os
2747
aws s3 cp s3://hybrid-staging.testsigma.com/testsigma_os $HOME/.testsigma_os --recursive
28-
env:
29-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
30-
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
31-
AWS_DEFAULT_REGION: 'us-east-1'
32-
AWS_DEFAULT_OUTPUT: json
33-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
34-
- name: Building
48+
49+
- name: Building
3550
run: |
3651
if [[ "${{ github.event.inputs.buildType }}" == "Testing" ]]; then
3752
bash agent/scripts/build.sh --VERSION=v${{ github.event.inputs.buildVersion }} --PUBLISH_TO_GIT=false
@@ -40,8 +55,5 @@ jobs:
4055
bash agent/scripts/build.sh --VERSION=v${{ github.event.inputs.buildVersion }} --PUBLISH_TO_GIT=true
4156
fi
4257
env:
43-
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
44-
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
45-
AWS_DEFAULT_REGION: 'us-east-1'
46-
AWS_DEFAULT_OUTPUT: json
47-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
58+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
59+

0 commit comments

Comments
 (0)