Repository navigation
env and secret commands: build environment and provider-held secrets - #36
Open
Interlap01 wants to merge 7 commits into
Open
Interlap01 wants to merge 7 commits into
Interlap01 wants to merge 7 commits into
Conversation
A top-level env applies to every build and a profile's env overrides it key by key. builder.json also lists the names of provider-held secrets (top level and per profile) a build exposes; only names, never values. The names travel in the profile dispatch input (sent now also without a profile when there is a top-level env or secret) and as BUILDER_SECRETS for runner.sh. Secret names are upper case, without a double underscore, and pass the same reserved-name checks as env.
The Resolve parameters step of ios-build.yml receives toJSON(secrets) and exports only the names builder.json lists, masking every line of each value first. A profile's build takes NAME__<PROFILE> when it exists, else NAME. runner.sh does the same over the provider's variables. A listed name without a value fails the job naming builder secret set.
GitHub: SetSecret seals the value with the repository key, DeleteSecret. Codemagic: secure variables in the app's builder variable group (v3 API), creating the group on first use, updating in place. Bitrise: app secrets, created protected with expansion and pull-request exposure off; an update sends only the value. All three list names only.
Edits the top-level env or a profile's (--profile) in builder.json with the same name checks a build applies, and refuses a name that is also a listed secret. env list --profile shows what that profile's builds get and where each value is set; --json for scripts.
set reads the value from a hidden prompt or --value-stdin (never argv, never printed), stores it on the provider (--provider, else the profile's, else builder.json's, else GitHub) as NAME, or NAME__<PROFILE> with --profile, and lists the name in builder.json. Name checks run before the value is asked for. unset deletes the stored value and the name; list shows each listed name, where it is stored and whether the provider has it, never a value.
README section on env and secret commands, per-profile values and the runner exposure; CLAUDE.md commands and patterns; the provider secrets guide points app secrets at builder secret set.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
builder env set|unset|list [--profile] [--json]: plain values in builder.json. New top-levelenvapplies to every build; a profile'senvoverrides it per key.builder secret set|unset|list [--profile] [--provider] [--json]: the value goes to the CI provider, only the name goes into builder.json (secrets, top level and per profile).buildervariable group (v3variable-groupsAPI; group created if missing).--value-stdin. It is never an argument and never printed. Every name check runs before the prompt.--profile productionstoresNAME__PRODUCTION. A build with that profile takes it when present, elseNAME, and exports it asNAMEin both cases. This works the same on all three providers. GitHub Environments are not used.Resolve parametersstep (and only that step) receives${{ toJSON(secrets) }}and exports only the listed names via the existing base64 + random-delimiter$GITHUB_ENVheredoc. Each line of a value gets::add-mask::before anything is written.profileJSON input. No new dispatch input. On tag builds they are read from builder.json.runner.sh(export_build_secrets) does the same over the provider's variables.builder secret set.__.IOS_*,MOBAI_API_KEY,GITHUB_*, and so on.ios buildrefuses secrets when the localios-build.ymlpredates them, because an older workflow would silently ignore the list.Why
Roadmap item 8 (environment and secrets profiles), in the style of EAS: build-time config in the repo, secrets kept on the CI provider, with no dashboard steps.
How tested
Resolve parametersscript runs against a faketoJSON(secrets)value. Tests check that it exports exactly the listed secrets, prefers the profile value, masks every line, never prints unlisted values, and fails on missing, invalid or conflicting names.runner.shfunction runs under bash with the same cases.go test -race ./...,go vet,gofmtand golangci-lint v2.12.2 (the version CI uses) are all clean. No live runs against GitHub, Codemagic or Bitrise.Left out
ios sharegets no env or secrets, unchanged from before (its workflow takes no profile).ios build/ios releaseonly. Organisation-level secrets (Bitrise org, Codemagic team groups) are not managed.builder signing setupstill uploads signing sets only to GitHub.