Files
twenty/.github/workflows/cd-deploy-main.yaml
Paul Rastoin d5c7b735d2 ci: migrate cross-repo dispatch senders to workflow_dispatch (actions:write) (#21648)
# Introduction
Getting rid of the fine grained PAT used to dispatch to internal
repositories.
Repo dispatch requires the contents write permissions which is too wide
for such use
Refactored all senders and target to pass through a workflow dispatch
instead
Creating a centralize app that forges a token with actions: write only
provided permissions to mitigate any token exfiltrations
2026-06-16 15:18:43 +02:00

31 lines
816 B
YAML

name: CD deploy main
permissions:
contents: read
on:
push:
branches:
- main
jobs:
deploy-main:
timeout-minutes: 3
runs-on: ubuntu-latest
steps:
- name: Mint twenty-infra dispatch token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ vars.TWENTY_WORKFLOW_DISPATCHER_CLIENT_ID }}
private-key: ${{ secrets.TWENTY_WORKFLOW_DISPATCHER_PRIVATE_KEY }}
owner: twentyhq
repositories: twenty-infra
permission-actions: write
- name: Trigger twenty-infra deploy
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
gh workflow run auto-deploy-main.yaml --repo twentyhq/twenty-infra --ref main