diff --git a/.github/workflows/deploy-proxy-latha-org.yml b/.github/workflows/deploy-proxy-latha-org.yml index 4dd56d6..8f634b6 100644 --- a/.github/workflows/deploy-proxy-latha-org.yml +++ b/.github/workflows/deploy-proxy-latha-org.yml @@ -5,24 +5,25 @@ # of its own — OpenBao (same secret store cachix.yml already pulls from) # is the only place they live outside a human's own machine. # -# Expects CLOUDFLARE_API_TOKEN and BUILDBUDDY_API_KEY under OpenBao's -# secret/data/ai-api-keys (or wherever OPENBAO_SECRET_PATH points) — see -# deploy.sh's own header comment for what each one needs to be able to do. -# If either is missing, fetch-openbao-env.sh fails loudly (no -# partial/silent deploy). +# Expects CLOUDFLARE_API_TOKEN under OpenBao's secret/data/ai-api-keys (or +# wherever OPENBAO_SECRET_PATH points). If missing, fetch-openbao-env.sh +# fails loudly (no partial/silent deploy). # # CLOUDFLARE_ACCOUNT_ID isn't a secret in the same sense — not stored in # OpenBao, just resolved live from the API token itself (GET /accounts). # -# TANGLED_WEBHOOK_SECRET and UPLOAD_TOKEN are read from OpenBao if already -# present there, else generated fresh + persisted back (so later runs -# reuse the same value instead of rotating on every deploy — deploy.sh -# overwrites the live Worker's secret bindings each run, and Tangled's own -# webhook config has to match TANGLED_WEBHOOK_SECRET independently). If -# this run generates a *new* TANGLED_WEBHOOK_SECRET (first-ever run, or -# OpenBao's copy was deleted), the job log prints it unmasked — someone -# needs to paste it into Tangled's Settings → Hooks → Secret for this repo -# afterward, or webhook deliveries will 401 until that's done. +# BUILDBUDDY_API_KEY, TANGLED_WEBHOOK_SECRET and UPLOAD_TOKEN are read +# from OpenBao if already present there, else seeded/generated + persisted +# back (so later runs reuse the same value instead of rotating on every +# deploy — deploy.sh overwrites the live Worker's secret bindings each +# run). BUILDBUDDY_API_KEY isn't randomly generated if missing — it has to +# be the real org key from https://app.buildbuddy.io/ → Settings, so a +# missing copy falls back to the repo secret BUILDBUDDY_API_KEY_FALLBACK +# (never written into any tracked file — same reason .buckconfig.local, +# which holds this same key locally, is gitignored). Only +# TANGLED_WEBHOOK_SECRET has an external dependency (Tangled's own +# Settings → Hooks → Secret config must match), so a freshly generated one +# is printed in the job log as a one-time follow-up instruction. name: Deploy proxy.latha.org on: @@ -52,22 +53,34 @@ jobs: fi chmod +x scripts/fetch-openbao-env.sh ./scripts/fetch-openbao-env.sh --github-env --keys \ - CLOUDFLARE_API_TOKEN,BUILDBUDDY_API_KEY + CLOUDFLARE_API_TOKEN - - name: Read or generate TANGLED_WEBHOOK_SECRET / UPLOAD_TOKEN + - name: Read or seed/generate BUILDBUDDY_API_KEY / TANGLED_WEBHOOK_SECRET / UPLOAD_TOKEN env: OPENBAO_ADDR: https://openbao.boxd.sh OPENBAO_TOKEN: ${{ secrets.OPENBAO_TOKEN }} OPENBAO_SECRET_PATH: secret/data/ai-api-keys + # Repo secret, not a literal value in source — see the header + # comment above for why. Only used as a fallback if OpenBao + # doesn't already have its own BUILDBUDDY_API_KEY. + KNOWN_BUILDBUDDY_API_KEY: ${{ secrets.BUILDBUDDY_API_KEY_FALLBACK }} run: | set -euo pipefail chmod +x scripts/openbao-put-key.sh - for key in TANGLED_WEBHOOK_SECRET UPLOAD_TOKEN; do + for key in BUILDBUDDY_API_KEY TANGLED_WEBHOOK_SECRET UPLOAD_TOKEN; do if exports="$(./scripts/fetch-openbao-env.sh --export --keys "$key" 2>/dev/null)"; then eval "$exports" echo "using existing $key from OpenBao" else - val="$(openssl rand -hex 32)" + if [[ "$key" == "BUILDBUDDY_API_KEY" ]]; then + if [[ -z "${KNOWN_BUILDBUDDY_API_KEY:-}" ]]; then + echo "BUILDBUDDY_API_KEY missing from OpenBao and no BUILDBUDDY_API_KEY_FALLBACK repo secret set" >&2 + exit 1 + fi + val="$KNOWN_BUILDBUDDY_API_KEY" + else + val="$(openssl rand -hex 32)" + fi ./scripts/openbao-put-key.sh "$key" --value "$val" >/dev/null export "$key=$val" if [[ "$key" == "TANGLED_WEBHOOK_SECRET" ]]; then @@ -75,7 +88,7 @@ jobs: echo " $val" else echo "::add-mask::$val" - echo "generated + stored a new $key in OpenBao" + echo "seeded/generated + stored a new $key in OpenBao" fi fi {