Skip to content

Commit 0d95dad

Browse files
authored
ci: use GitHub app for ephemeral tokens (#3808)
1 parent 33c8a02 commit 0d95dad

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

.buildkite/hooks/prepare-common.sh

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -37,9 +37,11 @@ fi
3737
java -version
3838

3939
echo "--- Prepare github secrets :vault:"
40-
VAULT_SECRET_PATH=kv/ci-shared/observability-ci/github-bot-user
41-
GITHUB_SECRET=$(vault kv get -field token "${VAULT_SECRET_PATH}")
42-
GIT_USER=$(vault kv get -field username "${VAULT_SECRET_PATH}")
43-
GIT_EMAIL=$(vault kv get -field email "${VAULT_SECRET_PATH}")
40+
# Only accessible by Elastic employees
41+
# The GitHub Permission Set can be found at:
42+
# https://github.com/v1v/terrazzo/blob/main/manifests/prod/vault/apm-agent-java-permission-set.yaml
43+
GITHUB_SECRET=$VAULT_GITHUB_TOKEN
44+
GIT_USER="elastic-vault-github-plugin-prod"
45+
GIT_EMAIL="[email protected]"
4446
GH_TOKEN=$GITHUB_SECRET
4547
export GITHUB_SECRET GH_TOKEN GIT_USER GIT_EMAIL

0 commit comments

Comments
 (0)