Add githubAppClientID as an alternative to githubAppID - #2168
Open
Erik-Schuetze wants to merge 1 commit into
Open
Erik-Schuetze wants to merge 1 commit into
Erik-Schuetze wants to merge 1 commit into
Conversation
Bump pkg/auth to v0.58.0 and pkg/runtime to v0.114.0 for the new KeyAppClientID constant and the updated GitHubAppDataFromSecret that accepts either a numeric App ID or an alphanumeric Client ID. Update the detection heuristic in the default provider case to trigger on githubAppClientID as well, add a test case, and document the new field in the GitRepository spec. Assisted-by: claude-code/claude-sonnet-5 Signed-off-by: Erik Schuetze <erik.schuetze@sap.com>
matheuscscp
approved these changes
Sep 29, 2026
matheuscscp
left a comment
Member
There was a problem hiding this comment.
LGTM! 🚀
@Erik-Schuetze We may need a PR in image-automation-controller as well, similar to what this PR is changing in gitrepository_controller.go 🙏
Member
|
@Erik-Schuetze The CI failures are due to our ongoing work regarding events. We will merge a PR to fix it and later ask you to rebase this one 🙏 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs: fluxcd/pkg#1291
Depends on (merged): fluxcd/pkg#1296
Depends on (merged): fluxcd/flux2#6085
GitHub Apps can be identified either by their numeric AppID or by their ClientID, and GitHub recommends the ClientID in the official docs. As of fluxcd/pkg#1296 (
auth/v0.58.0,runtime/v0.114.0),pkg/auth/githubappaccepts a ClientID as the JWTissclaim andpkg/runtime/secrets.GitHubAppDataFromSecretenforces exactly one of the two fields. This PR wires that into source-controller.Changes
go.mod: bumppkg/authv0.57.0 → v0.58.0 andpkg/runtimev0.112.0 → v0.114.0.gitrepository_controller.go: extend the thedefaultprovider case to also trigger ongithubAppClientID. (a clientID-only secret withoutprovider: githubproduces the same misconfiguration warning as for appID)gitrepository_controller_test.go: add a test case for the new branchdocs/spec/v1/gitrepositories.md: addgithubAppClientIDto the GitHub App secret YAML example alongsidegithubAppID, and document the exactly-one constraint (mirroring theinstallationOwner/installationIDparagraph below it).Behaviour
githubAppIDusage is unchanged.githubAppID/githubAppClientIDmust be provided; enforced bypkg/runtime/secrets.GitHubAppDataFromSecret(same pattern asinstallationOwner/installationID).getAuthOptsdelegates topkg/runtime/secretsandpkg/auth/githubapp, which already handle both fields.Tests
generic provider with github app client id in secrettoTestGitRepositoryReconciler_getAuthOpts_provider.go build ./internal/controller/,gofmt, and the relevant test function pass locally.