@@ -27,22 +27,21 @@ jobs:
2727 docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:c2f7cbbfb67ff9cad47e25ff8eb87945a4c5a0a81b2fa9e93a1d9ac6504a8df5 -c "cp /usr/bin/wolfictl /out"
2828 echo "$TMP" >> $GITHUB_PATH
2929
30- - name : ' Authenticate to Google Cloud'
30+ # This is managed here: https://github.com/chainguard-dev/secrets/blob/main/wolfi-dev.tf
31+ - uses : google-github-actions/auth@a6e2e39c0a0331da29f7fd2c2a20a427e8d3ad1f # v2.1.1
3132 id : auth
32- uses : google-github-actions/auth@f6de81663f7788d05bd15bcce18f0e57f23f0846 # v2.0.1
3333 with :
34- workload_identity_provider : " projects/618116202522/locations/global/workloadIdentityPools/prod-shared-e350/providers/prod-shared-gha"
35- service_account : " prod-images-ci@prod-images-c6e5.iam.gserviceaccount.com"
36-
34+ workload_identity_provider : " projects/12758742386/locations/global/workloadIdentityPools/github-pool/providers/github-provider"
35+ service_account : " wolfi-dev@chainguard-github-secrets.iam.gserviceaccount.com"
3736 - uses : google-github-actions/setup-gcloud@5a5f7b85fca43e76e53463acaa9d408a03c98d3a # v2.0.1
3837 with :
39- project_id : " prod-images-c6e5"
40-
38+ project_id : " chainguard-github-secrets"
4139 - uses : ' google-github-actions/get-secretmanager-secrets@ae0d4054c32840e2ced71207a9df55161ae3debc' # v2.0.0
4240 id : secrets
4341 with :
4442 secrets : |-
45- token:prod-images-c6e5/melange-signing-key
43+ token:chainguard-github-secrets/wolfi-dev-signing-key
44+
4645 - run : echo "${{ steps.secrets.outputs.token }}" > ./wolfi-signing.rsa
4746 - run : |
4847 sudo mkdir -p /etc/apk/keys
5655 curl https://packages.wolfi.dev/os/$arch/APKINDEX.tar.gz | wolfictl withdraw $(grep -v '\#' withdrawn-packages.txt) --signing-key="${{ github.workspace }}/wolfi-signing.rsa" > $arch/APKINDEX.tar.gz
5756 done
5857
58+ # We use a different GSA for our interaction with GCS.
59+ - uses : google-github-actions/auth@f6de81663f7788d05bd15bcce18f0e57f23f0846 # v2.0.1
60+ with :
61+ workload_identity_provider : " projects/618116202522/locations/global/workloadIdentityPools/prod-shared-e350/providers/prod-shared-gha"
62+ service_account : " prod-images-ci@prod-images-c6e5.iam.gserviceaccount.com"
63+ - uses : google-github-actions/setup-gcloud@5a5f7b85fca43e76e53463acaa9d408a03c98d3a # v2.0.1
64+ with :
65+ project_id : " prod-images-c6e5"
66+
5967 - name : Delete withdrawn packages
6068 run : |
6169 set -euo pipefail
0 commit comments