a5e5c7898055278887c3f7ba987d6818f9b5c6c9
Currently an external contributor can't have the acceptance tests run on their PR because pull_request doesn't give access to the secrets needed for them. Therefore, in this PR we create a new workflow that is identical to the one for existing acceptance tests, with the following differences: This workflow can be triggered with the command /ok-to-test sha="<contributor's latest commit sha>" by one of this repo's maintainers. After the acceptance tests finish, their result will be updated to the PR's list of checks.
Load Secrets from 1Password - GitHub Action
Provide the secrets your GitHub runner needs from 1Password.
load-secrets-action loads secrets from 1Password into GitHub Actions using Service Accounts or 1Password Connect.
Specify in your workflow YAML file which secrets from 1Password should be loaded into your job, and the action will make them available as environment variables for the next steps.
Read more on the 1Password Developer Portal.
🪄 See it in action!
✨ Quickstart
on: push
jobs:
hello-world:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Load secret
uses: 1password/load-secrets-action@v2
with:
# Export loaded secrets as environment variables
export-env: true
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }}
SECRET: op://app-cicd/hello-world/secret
- name: Print masked secret
run: 'echo "Secret: $SECRET"'
# Prints: Secret: ***
💙 Community & Support
- File an issue for bugs and feature requests.
- Join the Developer Slack workspace.
- Subscribe to the Developer Newsletter.
🔐 Security
1Password requests you practice responsible disclosure if you discover a vulnerability.
Please file requests by sending an email to bugbounty@agilebits.com.
Languages
TypeScript
86.4%
Shell
7.7%
JavaScript
5.9%
