diff --git a/docs/spec/v1/gitrepositories.md b/docs/spec/v1/gitrepositories.md index a2148f380..a700c460a 100644 --- a/docs/spec/v1/gitrepositories.md +++ b/docs/spec/v1/gitrepositories.md @@ -406,7 +406,7 @@ The `github` provider can be used to authenticate to Git repositories using The GitHub App information is specified in `.spec.secretRef` in the format specified below: -- Get the App ID from the app settings page at `https://github.com/settings/apps/`. +- Get the App ID or Client ID from the app settings page at `https://github.com/settings/apps/`. - The private key that was generated in the pre-requisites. - (Optional) GitHub Enterprise Server users can set the base URL to `http(s)://HOSTNAME/api/v3`. @@ -426,6 +426,7 @@ metadata: type: Opaque stringData: githubAppID: "" + githubAppClientID: "" githubAppInstallationOwner: "" githubAppInstallationID: "" githubAppPrivateKey: | @@ -439,6 +440,9 @@ stringData: -----END CERTIFICATE----- ``` +Exactly one of `githubAppID` or `githubAppClientID` must be provided. +If neither or both are provided, the reconciliation will fail with a misconfiguration error. + Exactly one of `githubAppInstallationOwner` or `githubAppInstallationID` must be provided. If neither or both are provided, the reconciliation will fail with a misconfiguration error. When `githubAppInstallationOwner` is provided, the controller will look for the installation diff --git a/go.mod b/go.mod index efd2d6b8f..2f7b555d2 100644 --- a/go.mod +++ b/go.mod @@ -26,7 +26,7 @@ require ( github.com/fluxcd/pkg/apis/event v0.30.0 github.com/fluxcd/pkg/apis/meta v1.32.0 github.com/fluxcd/pkg/artifact v0.21.0 - github.com/fluxcd/pkg/auth v0.57.0 + github.com/fluxcd/pkg/auth v0.58.0 github.com/fluxcd/pkg/cache v0.15.0 github.com/fluxcd/pkg/git v0.53.0 github.com/fluxcd/pkg/gittestserver v0.30.0 diff --git a/go.sum b/go.sum index 60aeb2440..65904358b 100644 --- a/go.sum +++ b/go.sum @@ -362,8 +362,8 @@ github.com/fluxcd/pkg/apis/meta v1.32.0 h1:jWuNuIziUM8NOrhZB7vovdFQ4wBYRNJoAn+XU github.com/fluxcd/pkg/apis/meta v1.32.0/go.mod h1:bZmU0RbSwFzsCg9sgjhbSWxgSbUy+3Oh/s7qUCZjwPk= github.com/fluxcd/pkg/artifact v0.21.0 h1:hUb2JacxhTLMNmFy8G6IvJxJLFvifNpCr7dDuEQscmo= github.com/fluxcd/pkg/artifact v0.21.0/go.mod h1:XZkvL7gtJoVTclRBrvwklW6PLazt00tT7TKDPhINZoU= -github.com/fluxcd/pkg/auth v0.57.0 h1:RJu5Sn8sel0/LZ0FyN/FL4juyQyOqIHHhL7nVV4GMAw= -github.com/fluxcd/pkg/auth v0.57.0/go.mod h1:aJYfAWHGN2332txF1EInn/N13A8CjpKPQRc8tCqvKmY= +github.com/fluxcd/pkg/auth v0.58.0 h1:2MUjD8rw1kZY4ULs5HLCAlw/DAdMMUXGvtKFt/wZyjo= +github.com/fluxcd/pkg/auth v0.58.0/go.mod h1:aJYfAWHGN2332txF1EInn/N13A8CjpKPQRc8tCqvKmY= github.com/fluxcd/pkg/cache v0.15.0 h1:/mb5nEFWKETY3cXdw2nfYuDZp7deFXDw479dBhQHzjc= github.com/fluxcd/pkg/cache v0.15.0/go.mod h1:Xttm38GeHpQCphCyTTuXSLeLE5psR7+DaSO4Ov28AEw= github.com/fluxcd/pkg/git v0.53.0 h1:wHtxfJ+qaNSQowaZB8Lr5adZO7psAsaID0E5W5QZREs= diff --git a/internal/controller/gitrepository_controller.go b/internal/controller/gitrepository_controller.go index 3ca4bb77f..8228037e3 100644 --- a/internal/controller/gitrepository_controller.go +++ b/internal/controller/gitrepository_controller.go @@ -798,7 +798,7 @@ func (r *GitRepositoryReconciler) getAuthOpts(ctx context.Context, obj *sourcev1 } default: // analyze secret, if it has github app data, perhaps provider should have been github. - if appID := authData[githubapp.KeyAppID]; len(appID) != 0 { + if len(authData[githubapp.KeyAppID]) != 0 || len(authData[githubapp.KeyAppClientID]) != 0 { e := serror.NewGeneric( fmt.Errorf("secretRef '%s/%s' has github app data but provider is not set to github", obj.GetNamespace(), obj.Spec.SecretRef.Name), sourcev1.InvalidProviderConfigurationReason, diff --git a/internal/controller/gitrepository_controller_test.go b/internal/controller/gitrepository_controller_test.go index 1a6b182ad..79f8d975d 100644 --- a/internal/controller/gitrepository_controller_test.go +++ b/internal/controller/gitrepository_controller_test.go @@ -1028,6 +1028,25 @@ func TestGitRepositoryReconciler_getAuthOpts_provider(t *testing.T) { }, wantErr: "secretRef '/githubAppSecret' has github app data but provider is not set to github", }, + { + name: "generic provider with github app client id in secret", + url: "https://example.com/org/repo", + secret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: "githubAppSecret", + }, + Data: map[string][]byte{ + githubapp.KeyAppClientID: []byte("Iv23liXXXXXXX"), + }, + }, + beforeFunc: func(obj *sourcev1.GitRepository) { + obj.Spec.Provider = sourcev1.GitProviderGeneric + obj.Spec.SecretRef = &meta.LocalObjectReference{ + Name: "githubAppSecret", + } + }, + wantErr: "secretRef '/githubAppSecret' has github app data but provider is not set to github", + }, { name: "github provider with basic auth secret", url: "https://github.com/org/repo.git",