Compare commits

..

2 Commits

Author SHA1 Message Date
CrazyMax
2ca78c6bec
Merge pull request #1595 from crazy-max/dockerhub-oidc
Some checks failed
ci / multi-output (push) Has been cancelled
ci / load-and-push (push) Has been cancelled
ci / summary-disable (push) Has been cancelled
ci / summary-not-supported (push) Has been cancelled
ci / record-upload-disable (push) Has been cancelled
ci / record-retention-days (0) (push) Has been cancelled
ci / record-retention-days (2) (push) Has been cancelled
ci / checks (edge) (push) Has been cancelled
ci / checks (latest) (push) Has been cancelled
ci / checks (v0.14.1) (push) Has been cancelled
ci / annotations-disabled (push) Has been cancelled
ci / call-check (push) Has been cancelled
ci / no-default-attestations (push) Has been cancelled
codeql / analyze (push) Has been cancelled
e2e / build (AWS ECR Public, aws, public.ecr.aws, public.ecr.aws/q3b5f1u4/test-docker-action, remote) (push) Has been cancelled
e2e / build (AWS ECR, aws, 175142243308.dkr.ecr.us-east-2.amazonaws.com, 175142243308.dkr.ecr.us-east-2.amazonaws.com/sandbox/test-docker-action, remote) (push) Has been cancelled
e2e / build (Artifactory, artifactory, infradock.jfrog.io, infradock.jfrog.io/test-ghaction/build-push-action, remote) (push) Has been cancelled
e2e / build (Azure Container Registry, acr, officialgithubactions.azurecr.io, officialgithubactions.azurecr.io/test-docker-action, remote) (push) Has been cancelled
e2e / build (Docker Hub, dockerhub, , dockereng/build-push-action-test, remote) (push) Has been cancelled
e2e / build (GitHub, ghcr, ghcr.io, ghcr.io/docker/build-push-action-test, remote) (push) Has been cancelled
e2e / build (GitLab, gitlab, registry.gitlab.com, registry.gitlab.com/test1716/test, remote) (push) Has been cancelled
e2e / build (Google Artifact Registry, gar, us-east4-docker.pkg.dev, us-east4-docker.pkg.dev/sandbox-298914/docker-official-github-actions/test-docker-action, remote) (push) Has been cancelled
e2e / build (Quay, quay, quay.io, quay.io/docker_build_team/ghactiontest, remote) (push) Has been cancelled
e2e / build (distribution, Distribution, none, local) (push) Has been cancelled
e2e / build (harbor, Harbor, none, local) (push) Has been cancelled
e2e / build (nexus, Nexus, none, local) (push) Has been cancelled
test / test (push) Has been cancelled
validate / prepare (push) Has been cancelled
zizmor / zizmor (push) Has been cancelled
validate / validate (push) Has been cancelled
ci(e2e): use Docker Hub OIDC for test image
2026-08-10 19:39:20 +02:00
CrazyMax
2a30ab2a50
ci(e2e): use Docker Hub OIDC for test image
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-08-06 10:16:17 +02:00
2 changed files with 5 additions and 4 deletions

View File

@ -130,6 +130,8 @@ jobs:
name: Login to Registry name: Login to Registry
if: github.event_name != 'pull_request' && (inputs.type == 'remote' || inputs.provider == 'aws' || env.REGISTRY_USER != '') if: github.event_name != 'pull_request' && (inputs.type == 'remote' || inputs.provider == 'aws' || env.REGISTRY_USER != '')
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ inputs.provider == 'dockerhub' && vars.DOCKERHUB_OIDC_CONNECTIONID || '' }}
with: with:
registry: ${{ env.REGISTRY_FQDN || inputs.registry }} registry: ${{ env.REGISTRY_FQDN || inputs.registry }}
username: ${{ env.REGISTRY_USER || secrets.registry_username || (inputs.registry == 'ghcr.io' && github.actor) || '' }} username: ${{ env.REGISTRY_USER || secrets.registry_username || (inputs.registry == 'ghcr.io' && github.actor) || '' }}

View File

@ -22,7 +22,7 @@ jobs:
uses: ./.github/workflows/.e2e-run.yml uses: ./.github/workflows/.e2e-run.yml
permissions: permissions:
contents: read contents: read
id-token: write # to get AWS credentials id-token: write # to get Docker Hub and AWS credentials
packages: write # to push image to GHCR packages: write # to push image to GHCR
strategy: strategy:
fail-fast: false fail-fast: false
@ -107,10 +107,10 @@ jobs:
secrets: secrets:
# Pass only the registry-specific secrets needed by each matrix entry. # Pass only the registry-specific secrets needed by each matrix entry.
# GHCR uses the called workflow's GITHUB_TOKEN fallback. # GHCR uses the called workflow's GITHUB_TOKEN fallback.
# AWS ECR uses OIDC to get credentials. # Docker Hub and AWS ECR use OIDC to get credentials.
registry_username: >- registry_username: >-
${{ ${{
matrix.provider == 'dockerhub' && vars.DOCKERPUBLICBOT_USERNAME || matrix.provider == 'dockerhub' && 'dockereng' ||
matrix.provider == 'gitlab' && secrets.GITLAB_USERNAME || matrix.provider == 'gitlab' && secrets.GITLAB_USERNAME ||
matrix.provider == 'gar' && secrets.GAR_USERNAME || matrix.provider == 'gar' && secrets.GAR_USERNAME ||
matrix.provider == 'acr' && secrets.AZURE_CLIENT_ID || matrix.provider == 'acr' && secrets.AZURE_CLIENT_ID ||
@ -120,7 +120,6 @@ jobs:
}} }}
registry_password: >- registry_password: >-
${{ ${{
matrix.provider == 'dockerhub' && secrets.DOCKERPUBLICBOT_WRITE_PAT ||
matrix.provider == 'gitlab' && secrets.GITLAB_TOKEN || matrix.provider == 'gitlab' && secrets.GITLAB_TOKEN ||
matrix.provider == 'gar' && secrets.GAR_JSON_KEY || matrix.provider == 'gar' && secrets.GAR_JSON_KEY ||
matrix.provider == 'acr' && secrets.AZURE_CLIENT_SECRET || matrix.provider == 'acr' && secrets.AZURE_CLIENT_SECRET ||