fix(release): read VAULT_ADDR from vars, not secrets #8
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/release-vault-addr-var"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Every release run since v0.1.0 has failed at the "Guard required secrets" step (~8s runtime each time) -- confirmed by checking configured secrets/vars via the API. Root cause: VAULT_ADDR is set at the org level as an Actions variable, but the workflow read it as
secrets.VAULT_ADDR, which always resolves empty. Fixed here to readvars.VAULT_ADDRinstead.This alone will not make a release succeed yet -- two more things are still missing and need to be supplied by a human before the next tag push can complete: (1) GPG_PRIVATE_KEY / GPG_PASSPHRASE secrets (org or repo level) for signing the release -- not present anywhere currently; (2) the OpenBao KV entry at kv/ci/terraform-provider-dmarcing/boring-registry (aws_access_key_id, aws_secret_access_key, s3_bucket, s3_endpoint, s3_region) is empty -- the JWT auth role itself is correctly configured server-side, just the underlying secret data was never populated.