Skip to content

Conversation

@oioki
Copy link
Member

@oioki oioki commented Apr 30, 2025

Switch collect-and-deploy job to workload identity. This will allow us to get rid of static GCP credentials GOOGLE_APPLICATION_CREDENTIALS.

@oioki oioki requested a review from a team April 30, 2025 19:00
Copy link
Contributor

@asottile-sentry asottile-sentry left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added a package so we can know sooner rather than later if this is broken

@asottile-sentry asottile-sentry merged commit 9834d7f into main Apr 30, 2025
14 checks passed
@asottile-sentry asottile-sentry deleted the fix/gha-oidc-collect-and-deploy branch April 30, 2025 19:05
@asottile-sentry
Copy link
Contributor

this did not work

@asottile-sentry
Copy link
Contributor

https://github.com/getsentry/pypi/actions/runs/14762315323/job/41445785900

ServiceException: 401 Anonymous caller does not have storage.objects.create access to the Google Cloud Storage object. Permission 'storage.objects.create' denied on resource (or it may not exist).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants