From 7a4e06b82b36c6930c251e3fc97dc522bc8bb659 Mon Sep 17 00:00:00 2001 From: Fede Barcelona Date: Thu, 10 Sep 2026 11:32:18 +0200 Subject: [PATCH] ci: pick Secure API token secret by cluster in scan.yaml Add a workflow_dispatch choice input (kube/kubelab) so manual runs can target either cluster's Sysdig Secure token without editing the workflow. Resolved inline per step rather than as a workflow-level env var, so the token isn't exposed to jobs/steps that don't need it. --- .github/workflows/scan.yaml | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/.github/workflows/scan.yaml b/.github/workflows/scan.yaml index 0ff348b..eb91537 100644 --- a/.github/workflows/scan.yaml +++ b/.github/workflows/scan.yaml @@ -2,6 +2,15 @@ name: Scan Image on: workflow_dispatch: + inputs: + cluster: + description: "Cluster whose Secure API token secret to use" + required: true + default: kube + type: choice + options: + - kube + - kubelab jobs: scan-from-registry: @@ -19,7 +28,7 @@ jobs: # Tag of the image to analyse image-tag: sysdiglabs/dummy-vuln-app:latest # API token for Sysdig Scanning auth - sysdig-secure-token: ${{ secrets.KUBELAB_SECURE_API_TOKEN }} + sysdig-secure-token: ${{ inputs.cluster == 'kubelab' && secrets.KUBELAB_SECURE_API_TOKEN || secrets.KUBE_SECURE_API_TOKEN }} stop-on-failed-policy-eval: true stop-on-processing-error: true severity-at-least: medium @@ -45,7 +54,7 @@ jobs: # Tag of the image to analyse image-tag: sysdiglabs/dummy-vuln-app:latest # API token for Sysdig Scanning auth - sysdig-secure-token: ${{ secrets.KUBELAB_SECURE_API_TOKEN }} + sysdig-secure-token: ${{ inputs.cluster == 'kubelab' && secrets.KUBELAB_SECURE_API_TOKEN || secrets.KUBE_SECURE_API_TOKEN }} stop-on-failed-policy-eval: true stop-on-processing-error: true severity-at-least: medium @@ -72,7 +81,7 @@ jobs: # Tag of the image to analyse image-tag: sysdiglabs/dummy-vuln-app:latest # API token for Sysdig Scanning auth - sysdig-secure-token: ${{ secrets.KUBELAB_SECURE_API_TOKEN }} + sysdig-secure-token: ${{ inputs.cluster == 'kubelab' && secrets.KUBELAB_SECURE_API_TOKEN || secrets.KUBE_SECURE_API_TOKEN }} stop-on-failed-policy-eval: false stop-on-processing-error: true skip-summary: true @@ -84,7 +93,7 @@ jobs: # Tag of the image to analyse image-tag: sysdiglabs/dummy-vuln-app:latest # API token for Sysdig Scanning auth - #sysdig-secure-token: ${{ secrets.KUBELAB_SECURE_API_TOKEN }} + #sysdig-secure-token: ${{ inputs.cluster == 'kubelab' && secrets.KUBELAB_SECURE_API_TOKEN || secrets.KUBE_SECURE_API_TOKEN }} stop-on-failed-policy-eval: true stop-on-processing-error: true standalone: true @@ -110,7 +119,7 @@ jobs: # Tag of the image to analyse image-tag: hello-world:latest # This one should never have vulns # API token for Sysdig Scanning auth - sysdig-secure-token: ${{ secrets.KUBELAB_SECURE_API_TOKEN }} + sysdig-secure-token: ${{ inputs.cluster == 'kubelab' && secrets.KUBELAB_SECURE_API_TOKEN || secrets.KUBE_SECURE_API_TOKEN }} stop-on-failed-policy-eval: true stop-on-processing-error: true severity-at-least: medium