You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Set up deploys from GitHub Actions: trust policy, deploy role and workflow #1788
Since Harper 5.3.0, a GitHub Actions run can deploy with no stored credential. It trades its OIDC token for a one-hour operation token under a trust policy (HarperFast/harper#2171), and acts as a user whose role can deploy and do nothing else (HarperFast/harper#2809). Studio has nothing for this:
No trust-policy UI. Studio has no UI for add_oidc_trust, list_oidc_trust or drop_oidc_trust, and these operations aren't in the operations catalog.
The CLI tab is out of date. New Application → CLI (useCLISteps.tsx) tells people to run npm create harper with --deploymentUsername and save their password in .env. create-harper no longer asks for a username or a password.
Dead GitHub code.src/integrations/github/ has a repository and tags client that nothing uses.
Proposal
Add a Deploy from GitHub panel to an application, for super users on 5.3.0+.
Inputs. The panel asks for:
the GitHub repository;
the branch (main by default);
the environment (production by default);
the workflow path (.github/workflows/deploy.yaml by default, as create-harper scaffolds it).
Trust policies list. A cluster-level list of trust policies, from list_oidc_trust. Each entry shows what the policy trusts, the user it acts as and its operations. When a policy can't match anything, the entry shows its invalid_reason. Policies can be dropped, or disabled by saving them with enabled: false, from the list.
Also:
Make GATE_INERT_OPERATIONS version-aware, so those operations show as inert only before 5.3.0.
Add the OIDC trust operations to the operations catalog as super-user only. Their handlers enforce that too.
Update New Application → CLI to the current create-harper flow: harper login, then deploy on merge to main.
HarperFast/central-manager#904 creates the same three objects for PR previews, through central manager, with a component-scoped role. Production deploys don't need central manager, because Studio can call the cluster as the signed-in super user, but the shapes should stay the same.
A user starts from a new repository and a 5.3+ cluster. They fill in the panel, commit the workflow it shows and set the variable, and the next merge to main deploys with no secret in GitHub. The trust policies list flags a policy that can't match, with its reason.
Part of HarperFast/create-harper#143.
Problem
Since Harper 5.3.0, a GitHub Actions run can deploy with no stored credential. It trades its OIDC token for a one-hour operation token under a trust policy (HarperFast/harper#2171), and acts as a user whose role can deploy and do nothing else (HarperFast/harper#2809). Studio has nothing for this:
add_oidc_trust,list_oidc_trustordrop_oidc_trust, and these operations aren't in the operations catalog.deploy_component,drop_component,package_componentandrestart_serviceas granting nothing on every 5.x (GATE_INERT_OPERATIONS, from role operations allowlist: grants are gate-inert for ops registered without api_name (deploy_component, get_status, …); sql bypasses the allowlist harper#2175). That stopped being true in 5.3.0, so today the editor would tell someone their CI role can't deploy.useCLISteps.tsx) tells people to runnpm create harperwith--deploymentUsernameand save their password in.env. create-harper no longer asks for a username or a password.src/integrations/github/has a repository and tags client that nothing uses.Proposal
Add a Deploy from GitHub panel to an application, for super users on 5.3.0+.
Inputs. The panel asks for:
mainby default);productionby default);.github/workflows/deploy.yamlby default, as create-harper scaffolds it).It resolves the repository's numeric id through GitHub's API. For a private repository, the user pastes the id or grants GitHub access (Use OAuth for accessing private repos for deployment #1312).
What it creates. It creates or updates the same three things as
npm run deploy:setup-ci(deploy:setup-ci: create the cluster's trust policy and deploy role once create-harper#145), so a project looks the same on the cluster whichever way it was set up:operations: ["deploy_component", "get_job"]and no table permissions.https://token.actions.githubusercontent.com;repository_id,workflow_refandenvironment;operations: the same list as the role.What to commit. It shows the workflow file to commit, which is the one create-harper scaffolds (Deploy on merge to
mainwith GitHub OIDC instead of a stored refresh token create-harper#144). It also shows theHARPER_CLI_TARGETvalue to set as a repository variable.Trust policies list. A cluster-level list of trust policies, from
list_oidc_trust. Each entry shows what the policy trusts, the user it acts as and its operations. When a policy can't match anything, the entry shows itsinvalid_reason. Policies can be dropped, or disabled by saving them withenabled: false, from the list.Also:
GATE_INERT_OPERATIONSversion-aware, so those operations show as inert only before 5.3.0.harper login, then deploy on merge tomain.Related
add_oidc_trustandlist_oidc_trust.Done when
A user starts from a new repository and a 5.3+ cluster. They fill in the panel, commit the workflow it shows and set the variable, and the next merge to
maindeploys with no secret in GitHub. The trust policies list flags a policy that can't match, with its reason.