Skip to content

Give CI a GitHub App token so it can read the private instrument submodules - #40

Closed
mikelangmayr wants to merge 1 commit into
mainfrom
mike/ci-private-submodule-access
Closed

mikelangmayr wants to merge 1 commit into
mainfrom
mike/ci-private-submodule-access

Conversation

@mikelangmayr

@mikelangmayr mikelangmayr commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor
  • Two instrument repositories are private, and a workflow's GITHUB_TOKEN cannot read another repository, so actions/checkout fails the moment it reaches them and every job dies in seconds before building anything
  • Each job that checks out submodules now mints a short-lived App token and passes it to checkout, which propagates it to the submodule fetches
  • Scope lives in the App installation rather than a repository list in five places, so adding a private instrument means installing the App on it, not editing workflows
  • Requires two repository secrets before it works, SUBMODULE_APP_CLIENT_ID and SUBMODULE_APP_PRIVATE_KEY, from an App with Contents: read installed on every instrument repository including the public ones
  • Documented in the development chapter, since a missing App is otherwise a mystifying failure
  • All four workflow files verified to parse, with every submodule checkout confirmed to carry the token

@astronomerdave

Copy link
Copy Markdown
Contributor

This would work but I'm removing the instrument submodules from the core. Each instrument repo will build itself and fetch the core, and the core's CI will test against an in-core reference instrument instead. After that, CI never needs to read an instrument repo, so I'd rather not set up an app with read access to all of them only to take it out again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants