mirror of
https://github.com/docker/login-action.git
synced 2026-07-28 12:43:04 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9d876d6c33 |
@@ -173,27 +173,6 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
|
username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
|
||||||
|
|
||||||
registry-auth-oidc:
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
id-token: write
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
-
|
|
||||||
name: Checkout
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
-
|
|
||||||
name: Login to registries
|
|
||||||
uses: ./
|
|
||||||
env:
|
|
||||||
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
|
|
||||||
with:
|
|
||||||
registry-auth: |
|
|
||||||
- username: ${{ vars.DOCKERHUB_OIDC_USERNAME }}
|
|
||||||
- registry: ghcr.io
|
|
||||||
username: ${{ github.actor }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
ecr:
|
ecr:
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
strategy:
|
strategy:
|
||||||
@@ -228,7 +207,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
-
|
-
|
||||||
name: Configure AWS Credentials
|
name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2
|
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
|
||||||
with:
|
with:
|
||||||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
@@ -256,7 +235,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
-
|
-
|
||||||
name: Configure AWS Credentials
|
name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2
|
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
|
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
@@ -303,7 +282,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
-
|
-
|
||||||
name: Configure AWS Credentials
|
name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2
|
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
|
||||||
with:
|
with:
|
||||||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
@@ -332,7 +311,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
-
|
-
|
||||||
name: Configure AWS Credentials
|
name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2
|
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
|
role-to-assume: arn:aws:iam::175142243308:role/official_gha_cicd_login_action
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
|
|||||||
@@ -648,38 +648,6 @@ jobs:
|
|||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
```
|
```
|
||||||
|
|
||||||
Docker Hub OIDC can also be used with `registry-auth`. Grant `id-token: write`,
|
|
||||||
set `DOCKERHUB_OIDC_CONNECTIONID`, pass the Docker Hub organization name as
|
|
||||||
`username`, and omit `password` for the Docker Hub object:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: ci
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: main
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
id-token: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
login:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
-
|
|
||||||
name: Login to registries
|
|
||||||
uses: docker/login-action@v4
|
|
||||||
env:
|
|
||||||
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
|
|
||||||
with:
|
|
||||||
registry-auth: |
|
|
||||||
- username: ${{ vars.DOCKERHUB_ORGANIZATION }}
|
|
||||||
- registry: ghcr.io
|
|
||||||
username: ${{ github.actor }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Set scopes for the authentication token
|
### Set scopes for the authentication token
|
||||||
|
|
||||||
The `scope` input allows limiting registry credentials to a specific repository
|
The `scope` input allows limiting registry credentials to a specific repository
|
||||||
|
|||||||
@@ -54,25 +54,6 @@ test('getAuthList skips secret masking when registry-auth password is absent', a
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
test('getAuthList supports password-less Docker Hub registry-auth for OIDC', async () => {
|
|
||||||
const [auth] = getAuthList({
|
|
||||||
registry: '',
|
|
||||||
username: '',
|
|
||||||
password: '',
|
|
||||||
scope: '',
|
|
||||||
ecr: '',
|
|
||||||
logout: true,
|
|
||||||
registryAuth: '- username: docker-org\n'
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(auth).toMatchObject({
|
|
||||||
registry: 'docker.io',
|
|
||||||
username: 'docker-org',
|
|
||||||
password: undefined,
|
|
||||||
ecr: 'auto'
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
test('getAuthList masks registry-auth password when present', async () => {
|
test('getAuthList masks registry-auth password when present', async () => {
|
||||||
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
|
const stdoutWriteSpy = vi.spyOn(process.stdout, 'write').mockImplementation(() => true);
|
||||||
getAuthList({
|
getAuthList({
|
||||||
|
|||||||
@@ -1,14 +1,8 @@
|
|||||||
import {afterEach, expect, test, vi} from 'vitest';
|
import {expect, test, vi} from 'vitest';
|
||||||
|
|
||||||
import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
|
import {Docker} from '@docker/actions-toolkit/lib/docker/docker.js';
|
||||||
|
|
||||||
import {login, loginStandard, logout} from '../src/docker.js';
|
import {loginStandard, logout} from '../src/docker.js';
|
||||||
import * as dockerhub from '../src/dockerhub.js';
|
|
||||||
|
|
||||||
afterEach(() => {
|
|
||||||
vi.restoreAllMocks();
|
|
||||||
delete process.env.DOCKERHUB_OIDC_CONNECTIONID;
|
|
||||||
});
|
|
||||||
|
|
||||||
test('loginStandard calls exec', async () => {
|
test('loginStandard calls exec', async () => {
|
||||||
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
|
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
|
||||||
@@ -38,37 +32,6 @@ test('loginStandard calls exec', async () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
test('login exchanges Docker Hub OIDC token for password-less auth', async () => {
|
|
||||||
process.env.DOCKERHUB_OIDC_CONNECTIONID = '123e4567-e89b-42d3-a456-426614174000';
|
|
||||||
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
|
|
||||||
return {
|
|
||||||
exitCode: 0,
|
|
||||||
stdout: '',
|
|
||||||
stderr: ''
|
|
||||||
};
|
|
||||||
});
|
|
||||||
const oidcSpy = vi.spyOn(dockerhub, 'getOIDCToken').mockResolvedValue({
|
|
||||||
username: 'docker-org',
|
|
||||||
token: 'hub-token'
|
|
||||||
});
|
|
||||||
|
|
||||||
await login({
|
|
||||||
registry: 'docker.io',
|
|
||||||
username: 'docker-org',
|
|
||||||
password: '',
|
|
||||||
scope: '',
|
|
||||||
ecr: 'auto',
|
|
||||||
configDir: ''
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(oidcSpy).toHaveBeenCalledWith('docker.io', 'docker-org');
|
|
||||||
expect(execSpy).toHaveBeenCalledWith(['login', '--password-stdin', '--username', 'docker-org', 'docker.io'], {
|
|
||||||
input: Buffer.from('hub-token'),
|
|
||||||
silent: true,
|
|
||||||
ignoreReturnCode: true
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
test('logout calls exec', async () => {
|
test('logout calls exec', async () => {
|
||||||
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
|
const execSpy = vi.spyOn(Docker, 'getExecOutput').mockImplementation(async () => {
|
||||||
return {
|
return {
|
||||||
|
|||||||
@@ -126,14 +126,8 @@ describe('getOIDCToken', () => {
|
|||||||
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC token request rate limited, retrying in 0ms (attempt 1/5)');
|
expect(core.info).toHaveBeenCalledWith('Docker Hub OIDC token request rate limited, retrying in 0ms (attempt 1/5)');
|
||||||
});
|
});
|
||||||
|
|
||||||
test('throws Docker Hub OIDC error responses', async () => {
|
test('throws Docker Hub API errors', async () => {
|
||||||
postSpy.mockResolvedValue(httpResponse(400, JSON.stringify({error: 'invalid_request', error_description: 'bad connection', error_uri: 'https://docs.docker.com'})));
|
postSpy.mockResolvedValue(httpResponse(400, JSON.stringify({description: 'bad connection'})));
|
||||||
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 400: {"error":"invalid_request","error_description":"bad connection","error_uri":"https://docs.docker.com"}');
|
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 400: bad connection');
|
||||||
});
|
|
||||||
|
|
||||||
test('throws rate limited Docker Hub OIDC error response after retries', async () => {
|
|
||||||
postSpy.mockResolvedValue(httpResponse(429, JSON.stringify({error: 'rate_limited', error_description: 'slow down'}), {'retry-after': '0'}));
|
|
||||||
await expect(dockerhub.getOIDCToken('docker.io', 'dbowie')).rejects.toThrow('Docker Hub API: bad status code 429: {"error":"rate_limited","error_description":"slow down"}');
|
|
||||||
expect(postSpy).toHaveBeenCalledTimes(6);
|
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
+26
-26
File diff suppressed because one or more lines are too long
+3
-3
File diff suppressed because one or more lines are too long
+21
-13
@@ -12,14 +12,17 @@ interface OIDCTokenResponse {
|
|||||||
access_token: string;
|
access_token: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
const registries = new Set(['', 'docker.io', 'registry-1.docker.io', 'registry-1-stage.docker.io', 'dhi.io']);
|
|
||||||
const defaultExpiresIn = 300;
|
const defaultExpiresIn = 300;
|
||||||
const minExpiresIn = 300;
|
const minExpiresIn = 300;
|
||||||
const maxExpiresIn = 3600;
|
const maxExpiresIn = 3600;
|
||||||
const maxRetries = 5;
|
const maxRetries = 5;
|
||||||
|
|
||||||
export const isDockerHubOIDC = (registry: string, password: string): boolean => {
|
export const isDockerHubOIDC = (registry: string, password: string): boolean => {
|
||||||
return process.env.DOCKERHUB_OIDC_CONNECTIONID !== undefined && !password && registries.has(registry);
|
return process.env.DOCKERHUB_OIDC_CONNECTIONID !== undefined && !password && isDockerHubRegistry(registry);
|
||||||
|
};
|
||||||
|
|
||||||
|
const isDockerHubRegistry = (registry: string): boolean => {
|
||||||
|
return registry === '' || registry === 'docker.io' || registry === 'registry-1.docker.io' || registry === 'registry-1-stage.docker.io';
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getOIDCToken = async (registry: string, username: string): Promise<LoginCredentials> => {
|
export const getOIDCToken = async (registry: string, username: string): Promise<LoginCredentials> => {
|
||||||
@@ -108,19 +111,24 @@ const handleResponse = async (resp: httpm.HttpClientResponse): Promise<string> =
|
|||||||
};
|
};
|
||||||
|
|
||||||
const parseError = (statusCode: number, body: string): Error => {
|
const parseError = (statusCode: number, body: string): Error => {
|
||||||
if (body) {
|
|
||||||
let errResp: unknown;
|
|
||||||
try {
|
|
||||||
errResp = JSON.parse(body);
|
|
||||||
} catch {
|
|
||||||
errResp = undefined;
|
|
||||||
}
|
|
||||||
if (errResp !== undefined) {
|
|
||||||
throw new Error(`Docker Hub API: bad status code ${statusCode}: ${JSON.stringify(errResp)}`);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (statusCode === 401) {
|
if (statusCode === 401) {
|
||||||
throw new Error(`Docker Hub API: operation not permitted`);
|
throw new Error(`Docker Hub API: operation not permitted`);
|
||||||
}
|
}
|
||||||
|
if (body) {
|
||||||
|
const errResp = parseErrorBody(body);
|
||||||
|
for (const k of ['description', 'message', 'detail', 'error']) {
|
||||||
|
if (errResp[k]) {
|
||||||
|
throw new Error(`Docker Hub API: bad status code ${statusCode}: ${errResp[k]}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
throw new Error(`Docker Hub API: bad status code ${statusCode}`);
|
throw new Error(`Docker Hub API: bad status code ${statusCode}`);
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const parseErrorBody = (body: string): Record<string, string> => {
|
||||||
|
try {
|
||||||
|
return <Record<string, string>>JSON.parse(body);
|
||||||
|
} catch {
|
||||||
|
return {};
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user