Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
fc48f38
feat: implement Dex user provisioning and password hashing functionality
CasLubbers Sep 3, 2026
3165070
fix: add proto file to docker
CasLubbers Sep 3, 2026
a87e087
feat: allow to set initialPassword
CasLubbers Sep 8, 2026
82a0991
feat: editUser in dex mode to handle email immutability and password …
CasLubbers Sep 9, 2026
e4f3bb3
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Sep 9, 2026
f3498f2
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Sep 10, 2026
2674c9c
fix: copilot review comments
CasLubbers Sep 11, 2026
8247c6b
fix: review comments
CasLubbers Sep 16, 2026
500ad55
fix: review comments
CasLubbers Sep 16, 2026
63a2e36
fix: review comments
CasLubbers Sep 16, 2026
b1aa241
fix: review comments
CasLubbers Sep 17, 2026
2a7c40c
fix: add issuer to otomi
CasLubbers Sep 17, 2026
f489253
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Sep 18, 2026
b91a99f
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Sep 18, 2026
4853108
Merge remote-tracking branch 'origin/main' into APL-2079
CasLubbers Sep 18, 2026
0a25088
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Sep 18, 2026
b5e8fdb
fix: remove retries in dex client
CasLubbers Sep 23, 2026
1f54147
Merge remote-tracking branch 'origin/main' into APL-2079
CasLubbers Sep 23, 2026
a01d290
feat: add groupsClaimMapper
CasLubbers Sep 24, 2026
4f7a3d1
fix: review comments
CasLubbers Sep 29, 2026
5cc9f8d
fix: use dex-client-grpc package
CasLubbers Sep 29, 2026
16a430e
fix: add github token to build
CasLubbers Sep 29, 2026
947030d
fix: review comments
CasLubbers Sep 29, 2026
89de000
feat: move oidc settings under otomi
CasLubbers Sep 30, 2026
da51d88
Revert "feat: move oidc settings under otomi"
CasLubbers Oct 1, 2026
26afd28
fix: keep oidc top-level, add otomi.oidc.authenticationLayer only
CasLubbers Oct 1, 2026
9a369fa
Merge remote-tracking branch 'origin/main' into APL-2079
svcAPLBot Oct 1, 2026
2c7dc18
Merge remote-tracking branch 'origin/main' into APL-2079
CasLubbers Oct 2, 2026
b117d97
chore: Update npm registry URL in coverage.yml
CasLubbers Oct 2, 2026
ded2120
chore: Update npm registry URL for Linode in workflow
CasLubbers Oct 2, 2026
99d6fd0
chore: Update npm registry configuration for linode
CasLubbers Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@ jobs:
fetch-depth: 0
- name: Set npm token
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NODE_AUTH_TOKEN: ${{ secrets.BOT_TOKEN }}
run: |
echo "@linode:registry=https://npm.pkg.github.com/linode" > .npmrc
echo "@linode:registry=https://npm.pkg.github.com" > .npmrc
echo "//npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN}" >> .npmrc
echo '::set-output name=diff::1'

Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
# Required repository/environment secrets:
# OCI_USERNAME - registry login username
# DOCKERHUB_LINODEBOT_TOKEN - registry login token
# BOT_TOKEN - GitHub token with package read access, for npm install of @linode/*-client-grpc packages from GitHub Packages
name: Build test push release
on:
pull_request:
Expand Down Expand Up @@ -77,6 +78,8 @@ jobs:
tags: ${{ env.REGISTRY }}/${{ env.REPO }}:${{ steps.set_tag.outputs.tag }}
cache-from: type=gha
cache-to: type=gha,mode=max
secrets: |
NPM_TOKEN=${{ secrets.BOT_TOKEN }}
- name: Build, test
if: ${{ env.SHOULD_PUSH != 'true' }}
uses: docker/build-push-action@v7
Expand All @@ -85,3 +88,5 @@ jobs:
context: .
tags: not-used:tmp
cache-from: type=gha
secrets: |
NPM_TOKEN=${{ secrets.BOT_TOKEN }}
Comment thread
CasLubbers marked this conversation as resolved.
10 changes: 10 additions & 0 deletions .github/workflows/release-software.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Required repository/environment secrets:
# OCI_USERNAME - registry login username
# DOCKERHUB_LINODEBOT_TOKEN - registry login token
# BOT_TOKEN - GitHub token with package read access, for npm install of @linode/*-client-grpc packages from GitHub Packages
name: Release Software

on:
Expand Down Expand Up @@ -110,6 +111,8 @@ jobs:
build-args: |
VERSION=${{ env.GIT_TAG }}
tags: ${{ env.CONTAINER_IMAGE_TAG }}
secrets: |
NPM_TOKEN=${{ secrets.BOT_TOKEN }}

- name: Create GitHub Release
uses: linode/apl-gh-actions/actions/release-create-github-release@v0.4.0
Expand All @@ -124,6 +127,13 @@ jobs:
with:
node-version: 24

- name: Set npm token
env:
NODE_AUTH_TOKEN: ${{ secrets.BOT_TOKEN }}
run: |
echo "@linode:registry=https://npm.pkg.github.com" >> .npmrc
echo "//npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN}" >> .npmrc

- name: Build OpenAPI schema
run: |
npm ci
Expand Down
2 changes: 1 addition & 1 deletion .npmrc
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
# The redkubes at github packages is a proxy for all npm packages.
@redkubes:registry=https://npm.pkg.github.com/redkubes
@linode:registry=https://npm.pkg.github.com
engine-strict=true
9 changes: 7 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM node:24-alpine as ci

Check warning on line 1 in Dockerfile

View workflow job for this annotation

GitHub Actions / build-test-push-release

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

ENV NODE_ENV=test
ENV BLUEBIRD_DEBUG=0
Expand All @@ -9,11 +9,16 @@
WORKDIR /app

# Install dependencies before copying the full source code to take advantage of Docker layer caching
COPY package*.json ./
COPY package*.json .npmrc ./
# Needed for postinstall (build:models) during npm ci
COPY src/build-spec.ts ./src/build-spec.ts
COPY src/openapi ./src/openapi
RUN npm ci
# @linode/dex-client-grpc is hosted on GitHub Packages, which requires auth even for public pkg.
RUN --mount=type=secret,id=NPM_TOKEN \
cp .npmrc .npmrc.orig && \
echo "//npm.pkg.github.com/:_authToken=$(cat /run/secrets/NPM_TOKEN)" >> .npmrc && \
npm ci && \
mv .npmrc.orig .npmrc

COPY . .* ./
RUN npm run build
Expand All @@ -21,7 +26,7 @@
RUN npm run test

# --------------- Cleanup
FROM ci as clean

Check warning on line 29 in Dockerfile

View workflow job for this annotation

GitHub Actions / build-test-push-release

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/
# below command removes the packages specified in devDependencies and set NODE_ENV to production
RUN npm prune --production
# --------------- Production stage
Expand Down
Loading
Loading