mirror of
https://github.com/kyverno/kyverno.git
synced 2024-12-14 11:57:48 +00:00
chore: use github token instead of pat (#7716)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
parent
bec1f94f70
commit
52cb513571
1 changed files with 17 additions and 16 deletions
33
.github/workflows/images-publish.yaml
vendored
33
.github/workflows/images-publish.yaml
vendored
|
@ -10,14 +10,15 @@ concurrency:
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: ${{ github.workflow }}-${{ github.ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|
||||||
permissions:
|
permissions: {}
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
id-token: write
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
publish-images:
|
publish-images:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
packages: write
|
||||||
|
id-token: write
|
||||||
outputs:
|
outputs:
|
||||||
kyverno-digest: ${{ steps.publish-kyverno.outputs.digest }}
|
kyverno-digest: ${{ steps.publish-kyverno.outputs.digest }}
|
||||||
kyverno-init-digest: ${{ steps.publish-kyverno-init.outputs.digest }}
|
kyverno-init-digest: ${{ steps.publish-kyverno-init.outputs.digest }}
|
||||||
|
@ -51,7 +52,7 @@ jobs:
|
||||||
makefile-target: ko-publish-kyverno
|
makefile-target: ko-publish-kyverno
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -66,7 +67,7 @@ jobs:
|
||||||
makefile-target: ko-publish-kyverno-init
|
makefile-target: ko-publish-kyverno-init
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -81,7 +82,7 @@ jobs:
|
||||||
makefile-target: ko-publish-background-controller
|
makefile-target: ko-publish-background-controller
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -96,7 +97,7 @@ jobs:
|
||||||
makefile-target: ko-publish-cleanup-controller
|
makefile-target: ko-publish-cleanup-controller
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -111,7 +112,7 @@ jobs:
|
||||||
makefile-target: ko-publish-cli
|
makefile-target: ko-publish-cli
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -126,7 +127,7 @@ jobs:
|
||||||
makefile-target: ko-publish-reports-controller
|
makefile-target: ko-publish-reports-controller
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
repository: ${{ github.repository_owner }}
|
repository: ${{ github.repository_owner }}
|
||||||
version: ${{ github.ref_name }}
|
version: ${{ github.ref_name }}
|
||||||
sign-image: true
|
sign-image: true
|
||||||
|
@ -148,7 +149,7 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.kyverno-digest }}"
|
digest: "${{ needs.publish-images.outputs.kyverno-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
generate-kyverno-init-provenance:
|
generate-kyverno-init-provenance:
|
||||||
needs: publish-images
|
needs: publish-images
|
||||||
|
@ -163,7 +164,7 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.kyverno-init-digest }}"
|
digest: "${{ needs.publish-images.outputs.kyverno-init-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
generate-background-controller-provenance:
|
generate-background-controller-provenance:
|
||||||
needs: publish-images
|
needs: publish-images
|
||||||
|
@ -178,7 +179,7 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.background-controller-digest }}"
|
digest: "${{ needs.publish-images.outputs.background-controller-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
generate-cleanup-controller-provenance:
|
generate-cleanup-controller-provenance:
|
||||||
needs: publish-images
|
needs: publish-images
|
||||||
|
@ -193,7 +194,7 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.cleanup-controller-digest }}"
|
digest: "${{ needs.publish-images.outputs.cleanup-controller-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
generate-kyverno-cli-provenance:
|
generate-kyverno-cli-provenance:
|
||||||
needs: publish-images
|
needs: publish-images
|
||||||
|
@ -208,7 +209,7 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.cli-digest }}"
|
digest: "${{ needs.publish-images.outputs.cli-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
generate-reports-controller-provenance:
|
generate-reports-controller-provenance:
|
||||||
needs: publish-images
|
needs: publish-images
|
||||||
|
@ -223,4 +224,4 @@ jobs:
|
||||||
digest: "${{ needs.publish-images.outputs.reports-controller-digest }}"
|
digest: "${{ needs.publish-images.outputs.reports-controller-digest }}"
|
||||||
registry-username: ${{ github.actor }}
|
registry-username: ${{ github.actor }}
|
||||||
secrets:
|
secrets:
|
||||||
registry-password: ${{ secrets.CR_PAT }}
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
Loading…
Reference in a new issue