mirror of
https://github.com/jambonz/jambonz-feature-server.git
synced 2026-10-03 17:54:12 +00:00
This repo is public and held a long-lived AWS access key as repository secrets
(set 2023-11-22). It is replaced with short-lived credentials from the GitHub OIDC
provider; no AWS key and no account id remain in the repo.
create-test-db.js wrote {access_key_id, secret_access_key, aws_region} into the test
database as the aws speech credential, which sends speech-utils' getAwsAuthToken down
its access-key branch and calls GetSessionToken -- rejected by AWS for session
credentials. The role_arn branch calls AssumeRole instead, which accepts them, and is
already plumbed through db-utils.js, call-session.js and stt-task.js. The pinned
speech-utils 0.2.30 already supports it, so no dependency change is needed.
Fork pull requests receive neither secrets nor an OIDC token, so the credentials step
is guarded by a condition; the AWS tests then skip for forks exactly as they do today.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
41 lines
1.7 KiB
YAML
41 lines
1.7 KiB
YAML
name: CI
|
|
|
|
on: [push, pull_request]
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
id-token: write # required to request the GitHub OIDC token for AWS
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 20
|
|
# Pull requests from forks receive neither secrets nor an OIDC token, so this
|
|
# step is skipped for them; the AWS tests then skip too, exactly as they do
|
|
# today. Without the guard the step would hard-fail every fork PR.
|
|
- uses: aws-actions/configure-aws-credentials@v4
|
|
if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository
|
|
with:
|
|
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
|
|
aws-region: us-east-1
|
|
- run: npm ci
|
|
- run: npm run jslint
|
|
- name: Install Docker Compose
|
|
run: |
|
|
sudo curl -L "https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose
|
|
sudo chmod +x /usr/local/bin/docker-compose
|
|
docker-compose --version
|
|
- run: docker pull drachtio/sipp
|
|
- run: npm test
|
|
env:
|
|
GCP_JSON_KEY: ${{ secrets.GCP_JSON_KEY }}
|
|
# No AWS keys are stored as repository secrets. configure-aws-credentials
|
|
# above provides short-lived OIDC credentials, and AWS_ROLE_ARN makes the
|
|
# test speech credential use the AssumeRole path, which accepts them.
|
|
AWS_ROLE_ARN: ${{ secrets.AWS_ROLE_ARN }}
|
|
MICROSOFT_REGION: ${{ secrets.MICROSOFT_REGION }}
|
|
MICROSOFT_API_KEY: ${{ secrets.MICROSOFT_API_KEY }}
|