From cfadca9442678d5f0e0374e289c028636db753f9 Mon Sep 17 00:00:00 2001 From: Erik Schuetze Date: Tue, 29 Sep 2026 14:08:57 +0200 Subject: [PATCH] Add githubAppClientID as an alternative to githubAppID Bump pkg/auth to v0.58.0 and pkg/runtime to v0.114.0 for the new KeyAppClientID constant and the updated GitHubAppDataFromSecret that accepts either a numeric App ID or an alphanumeric Client ID. Update the detection heuristic in the default provider case to trigger on githubAppClientID as well, add a test case, and document the new field in the GitRepository spec. Assisted-by: claude-code/claude-sonnet-5 Signed-off-by: Erik Schuetze --- docs/spec/v1/gitrepositories.md | 6 +++++- go.mod | 4 ++-- go.sum | 4 ++++ .../controller/gitrepository_controller.go | 2 +- .../gitrepository_controller_test.go | 19 +++++++++++++++++++ 5 files changed, 31 insertions(+), 4 deletions(-) diff --git a/docs/spec/v1/gitrepositories.md b/docs/spec/v1/gitrepositories.md index 4c9d244af..5105c6864 100644 --- a/docs/spec/v1/gitrepositories.md +++ b/docs/spec/v1/gitrepositories.md @@ -406,7 +406,7 @@ The `github` provider can be used to authenticate to Git repositories using The GitHub App information is specified in `.spec.secretRef` in the format specified below: -- Get the App ID from the app settings page at `https://github.com/settings/apps/`. +- Get the App ID or Client ID from the app settings page at `https://github.com/settings/apps/`. - The private key that was generated in the pre-requisites. - (Optional) GitHub Enterprise Server users can set the base URL to `http(s)://HOSTNAME/api/v3`. @@ -426,6 +426,7 @@ metadata: type: Opaque stringData: githubAppID: "" + githubAppClientID: "" githubAppInstallationOwner: "" githubAppInstallationID: "" githubAppPrivateKey: | @@ -439,6 +440,9 @@ stringData: -----END CERTIFICATE----- ``` +Exactly one of `githubAppID` or `githubAppClientID` must be provided. +If neither or both are provided, the reconciliation will fail with a misconfiguration error. + Exactly one of `githubAppInstallationOwner` or `githubAppInstallationID` must be provided. If neither or both are provided, the reconciliation will fail with a misconfiguration error. When `githubAppInstallationOwner` is provided, the controller will look for the installation diff --git a/go.mod b/go.mod index c96f84dbd..2b53dac3e 100644 --- a/go.mod +++ b/go.mod @@ -26,7 +26,7 @@ require ( github.com/fluxcd/pkg/apis/event v0.29.0 github.com/fluxcd/pkg/apis/meta v1.32.0 github.com/fluxcd/pkg/artifact v0.21.0 - github.com/fluxcd/pkg/auth v0.57.0 + github.com/fluxcd/pkg/auth v0.58.0 github.com/fluxcd/pkg/cache v0.15.0 github.com/fluxcd/pkg/git v0.53.0 github.com/fluxcd/pkg/gittestserver v0.30.0 @@ -34,7 +34,7 @@ require ( github.com/fluxcd/pkg/http/transport v0.8.0 github.com/fluxcd/pkg/masktoken v0.9.0 github.com/fluxcd/pkg/oci v0.70.0 - github.com/fluxcd/pkg/runtime v0.112.0 + github.com/fluxcd/pkg/runtime v0.114.0 github.com/fluxcd/pkg/sourceignore v0.19.0 github.com/fluxcd/pkg/ssh v0.26.0 github.com/fluxcd/pkg/tar v1.2.0 diff --git a/go.sum b/go.sum index f26b51b7d..48598f47f 100644 --- a/go.sum +++ b/go.sum @@ -364,6 +364,8 @@ github.com/fluxcd/pkg/artifact v0.21.0 h1:hUb2JacxhTLMNmFy8G6IvJxJLFvifNpCr7dDuE github.com/fluxcd/pkg/artifact v0.21.0/go.mod h1:XZkvL7gtJoVTclRBrvwklW6PLazt00tT7TKDPhINZoU= github.com/fluxcd/pkg/auth v0.57.0 h1:RJu5Sn8sel0/LZ0FyN/FL4juyQyOqIHHhL7nVV4GMAw= github.com/fluxcd/pkg/auth v0.57.0/go.mod h1:aJYfAWHGN2332txF1EInn/N13A8CjpKPQRc8tCqvKmY= +github.com/fluxcd/pkg/auth v0.58.0 h1:2MUjD8rw1kZY4ULs5HLCAlw/DAdMMUXGvtKFt/wZyjo= +github.com/fluxcd/pkg/auth v0.58.0/go.mod h1:aJYfAWHGN2332txF1EInn/N13A8CjpKPQRc8tCqvKmY= github.com/fluxcd/pkg/cache v0.15.0 h1:/mb5nEFWKETY3cXdw2nfYuDZp7deFXDw479dBhQHzjc= github.com/fluxcd/pkg/cache v0.15.0/go.mod h1:Xttm38GeHpQCphCyTTuXSLeLE5psR7+DaSO4Ov28AEw= github.com/fluxcd/pkg/git v0.53.0 h1:wHtxfJ+qaNSQowaZB8Lr5adZO7psAsaID0E5W5QZREs= @@ -382,6 +384,8 @@ github.com/fluxcd/pkg/oci v0.70.0 h1:rylPalOomTmMPR/SYSEcADxo6XM1AUr62FMwLoubd0Y github.com/fluxcd/pkg/oci v0.70.0/go.mod h1:+mnv4AX8sGeCqFEF3xs9O04on8ByZNtq/ZQIHXJk0qU= github.com/fluxcd/pkg/runtime v0.112.0 h1:FnE+98Fg2LJYRBxMYGOIuE4C7nwtLMCXxFFJpMizdsA= github.com/fluxcd/pkg/runtime v0.112.0/go.mod h1:YUljTAXVaeWG+GLnXNZopFFMZstUoTxJs7+vl91OV58= +github.com/fluxcd/pkg/runtime v0.114.0 h1:uLQ92LeZEmxoFZhQoLUox7C13YUQ1WFYU28Bocl71mw= +github.com/fluxcd/pkg/runtime v0.114.0/go.mod h1:+h0Fyn5VfqFklfXxQJ0cuTxdS6RfE0qCwsSJa09vwy0= github.com/fluxcd/pkg/sourceignore v0.19.0 h1:s3/E03o9JTAvjIE7K8vI257AT2+0zy8cFOFaX+lx0z8= github.com/fluxcd/pkg/sourceignore v0.19.0/go.mod h1:MYwDEmDdj5GjHg1r1ljgtNkXNGkeV42G8BnCsggqExg= github.com/fluxcd/pkg/ssh v0.26.0 h1:fKw0gyZ2KgbngyI4zAzIfa0qnB4XjSpxBg1ZP6RySc8= diff --git a/internal/controller/gitrepository_controller.go b/internal/controller/gitrepository_controller.go index a3c27c9b6..b4e93b0bd 100644 --- a/internal/controller/gitrepository_controller.go +++ b/internal/controller/gitrepository_controller.go @@ -794,7 +794,7 @@ func (r *GitRepositoryReconciler) getAuthOpts(ctx context.Context, obj *sourcev1 } default: // analyze secret, if it has github app data, perhaps provider should have been github. - if appID := authData[githubapp.KeyAppID]; len(appID) != 0 { + if len(authData[githubapp.KeyAppID]) != 0 || len(authData[githubapp.KeyAppClientID]) != 0 { e := serror.NewGeneric( fmt.Errorf("secretRef '%s/%s' has github app data but provider is not set to github", obj.GetNamespace(), obj.Spec.SecretRef.Name), sourcev1.InvalidProviderConfigurationReason, diff --git a/internal/controller/gitrepository_controller_test.go b/internal/controller/gitrepository_controller_test.go index 84b2074a8..1880c3378 100644 --- a/internal/controller/gitrepository_controller_test.go +++ b/internal/controller/gitrepository_controller_test.go @@ -1028,6 +1028,25 @@ func TestGitRepositoryReconciler_getAuthOpts_provider(t *testing.T) { }, wantErr: "secretRef '/githubAppSecret' has github app data but provider is not set to github", }, + { + name: "generic provider with github app client id in secret", + url: "https://example.com/org/repo", + secret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: "githubAppSecret", + }, + Data: map[string][]byte{ + githubapp.KeyAppClientID: []byte("Iv23liXXXXXXX"), + }, + }, + beforeFunc: func(obj *sourcev1.GitRepository) { + obj.Spec.Provider = sourcev1.GitProviderGeneric + obj.Spec.SecretRef = &meta.LocalObjectReference{ + Name: "githubAppSecret", + } + }, + wantErr: "secretRef '/githubAppSecret' has github app data but provider is not set to github", + }, { name: "github provider with basic auth secret", url: "https://github.com/org/repo.git",