Skip to content

ci: Add support for OIDC - #440

Open
aanm wants to merge 1 commit into
mainfrom
pr/aanm/quay-oidc-robot-variables
Open

aanm wants to merge 1 commit into
mainfrom
pr/aanm/quay-oidc-robot-variables

Conversation

@aanm

@aanm aanm commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

This commit adds support for OIDC, replacing long-lived tokens. Quay.io
has been configured accordingly.

The robot account name is read from the QUAY_ROBOT_RELEASE variable,
defined on the GitHub environment the job pins rather than at repository
or organisation level, so the value a job receives is the one belonging
to its environment. The environment name also forms the OIDC subject
that the robot is configured to trust, so renaming the environment
breaks the login.

@aanm
aanm force-pushed the pr/aanm/quay-oidc-robot-variables branch from 82b8a5a to 391e8d6 Compare September 25, 2026 13:29
This commit adds support for OIDC, replacing long-lived tokens. Quay.io
has been configured accordingly.

The robot account name is read from the QUAY_ROBOT_RELEASE variable,
defined on the GitHub environment the job pins rather than at repository
or organisation level, so the value a job receives is the one belonging
to its environment. The environment name also forms the OIDC subject
that the robot is configured to trust, so renaming the environment
breaks the login.

Signed-off-by: André Martins <andre@cilium.io>
@aanm
aanm force-pushed the pr/aanm/quay-oidc-robot-variables branch from 391e8d6 to bcc6797 Compare September 25, 2026 14:47
@aanm
aanm marked this pull request as ready for review September 28, 2026 14:13
@aanm
aanm requested a review from joestringer September 29, 2026 08:20
permissions:
contents: read
# Required by the Quay OIDC token exchange.
id-token: write

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As far as I understand today, for pull_request triggers, the secrets are not made available to that PR (for external contributions), so the bare make command in the steps is not considered sensitive.

Does this hold true with this new method with id-token? Or would even pull_request triggered PRs gain an OIDC token and have the capability to escalate that to push access with arbitrary write?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we would have huge problems if that was the case. That's the reason why pull_request_target exists.
We can test it after merging but I'm 100% confident this won't work unless we use pull_request_target

@aanm
aanm requested a review from joestringer September 30, 2026 08:29

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants