From 5a6806f3d855b38b44b4a04d1708ea2416c1587b Mon Sep 17 00:00:00 2001 From: Andrei Jiroh Halili Date: Sun, 14 Sep 2025 00:29:43 +0800 Subject: [PATCH] feat: ship remote loader for dotenvx-encyrpted files outside the repo --- remote-loader/README.md | 33 ++++++++++++++++++++++++++++ remote-loader/action.yml | 47 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 80 insertions(+) create mode 100644 remote-loader/README.md create mode 100644 remote-loader/action.yml diff --git a/remote-loader/README.md b/remote-loader/README.md new file mode 100644 index 0000000..4121cfe --- /dev/null +++ b/remote-loader/README.md @@ -0,0 +1,33 @@ +# Remote `dotenvx` loader + +Loads `dotenvx`-encrypted secrets from a remote URL and decrypts them using a provided private key by combining both steps into one composite action. + +This is useful if you want to store your encrypted dotenv files in a separate repository or service, and load them dynamically during your CI/CD workflows. + +Note that releases for this action follow the same release cycle and cadence as the main action itself. + +## Usage + +```yaml +- uses: andreijiroh-dev/dotenvx-action/remote-loader@v0.4.0 # change this to latest tagged version or use commit hashes + id: dotenvx + with: + url: raw-url-here + key: ${{ secrets.DOTENV_PRIVATE_KEY_CI }} # for .env.ci + # optional if you need them in scripts involve requiring access to secrets via env vars + # inject-env-vars: "true" +``` + +### Inputs + +Other than [the regular options in the main action itself](../README.md#inputs), the only difference is the `url` input: + +| Input | Required | Description | +| ---------------- | -------- | ----------------------------------------------------------------------------------------------- | +| `url` | Yes | The raw URL to the dotenvx-encrypted file (e.g. from a repo). | + +Because this action fetches the dotenv file from a remote URL, you may need to ensure that the URL is accessible from the GitHub Actions runner environment (or utilize Actions secrets for adding URLs with any sensitive information in it, e.g. API keys in URL parameters). + +## License + +MIT diff --git a/remote-loader/action.yml b/remote-loader/action.yml new file mode 100644 index 0000000..c77bb49 --- /dev/null +++ b/remote-loader/action.yml @@ -0,0 +1,47 @@ +name: "Load dotenvx secrets from remote" +description: "Load secrets encrypted by dotenvx from a dotenv file hosted remotely" +author: ajhalili2006 +branding: + icon: lock + color: yellow + +inputs: + url: + description: URL to the remote dotenv file with dotenvx-encrypted secrets + required: true + key: + description: The value of `DOTENV_PRIVATE_KEY_CI` from your .env.keys file. + required: true + inject-env-vars: + description: Whether to inject decrypted secrets as environment variables for subsequent steps within the runner environment + default: "false" + +runs: + using: composite + steps: + - name: Fetch remote dotenv file + id: fetch + shell: bash + run: | + if [[ -z "${{ inputs.url }}" ]]; then + echo "Error: 'url' input is required." + exit 1 + fi + + # Fetch the remote dotenv file + response=$(curl -s -w "%{http_code}" -o /tmp/remote_env_file "${{ inputs.url }}") + http_code="${response: -3}" + + if [[ "$http_code" -ne 200 ]]; then + echo "Error: Failed to fetch the remote dotenv file. HTTP status code: $http_code" + exit 1 + fi + + echo "Remote dotenv file fetched successfully." + echo "path=/tmp/remote_env_file" >> $GITHUB_OUTPUT + - name: Load dotenvx secrets + uses: andreijiroh-dev/dotenvx-action@v0.4.0 + with: + path: ${{ steps.fetch.outputs.path }} + key: ${{ inputs.key }} + inject-env-vars: ${{ inputs.inject-env-vars }} -- 2.51.2