From 4900042c0faa6086d27e212ec53a2d02bd59f774 Mon Sep 17 00:00:00 2001 From: Xe Iaso Date: Sun, 10 May 2026 20:54:53 -0400 Subject: [PATCH] provider/tekton: fix service account name location Tekton v1beta1 PipelineRun objects[1] had the service account specified at the top level of spec, eg: ```yaml spec: serviceAccountName: tack ``` However Tekton v1 PipelineRun objects have the service account inside a `taskRunTemplate` object: ```yaml spec: taskRunTemplate: serviceAccountName: tack ``` This change properly places the service account name in the right place for Tekton v1 PipelineRun objects so that Tack can properly annotate CI pipelines with the right service account. [1]: https://tekton.dev/docs/pipelines/pipelineruns/#mapping-serviceaccount-credentials-to-tasks Signed-off-by: Xe Iaso --- provider_tekton.go | 4 +++- provider_tekton_test.go | 2 +- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/provider_tekton.go b/provider_tekton.go index d886f68..ce39c7c 100644 --- a/provider_tekton.go +++ b/provider_tekton.go @@ -368,7 +368,9 @@ func buildTektonPipelineRun( } if cfg.ServiceAccount != "" { - spec["serviceAccountName"] = cfg.ServiceAccount + spec["taskRunTemplate"] = map[string]any{ + "serviceAccountName": cfg.ServiceAccount, + } } // Merge user-defined params with the built-in ones (commit, diff --git a/provider_tekton_test.go b/provider_tekton_test.go index 2fbe56b..a4ccd67 100644 --- a/provider_tekton_test.go +++ b/provider_tekton_test.go @@ -113,7 +113,7 @@ func TestTektonBuildPipelineRun(t *testing.T) { if !ok || pipeline != "repo-ci" { t.Fatalf("pipelineRef.name = %q", pipeline) } - sa, ok := obj.NestedString("spec", "serviceAccountName") + sa, ok := obj.NestedString("spec", "taskRunTemplate", "serviceAccountName") if !ok || sa != "runner" { t.Fatalf("serviceAccountName = %q", sa) } -- 2.51.2