Skip to content

CP-8108: Use AWS Secrets Manager to store envs #35

CP-8108: Use AWS Secrets Manager to store envs

CP-8108: Use AWS Secrets Manager to store envs #35

name: Bitrise Envs Sync
on:
pull_request:
# The branches below must be a subset of the branches above
branches: ['development']
workflow_dispatch:
jobs:
upload-envs-to-bitrise:
name: Upload envs to Bitrise
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- name: Check out repo
uses: actions/checkout@v3
- uses: mcblair/[email protected]
with:
region: us-east-2
role-arn: arn:aws:iam::975050371175:role/github-sa-role
profile-name: test
# - name: Configure AWS Credentials Action for GitHub Actions
# uses: aws-actions/[email protected]
# with:
# aws-region: us-east-2
# role-to-assume: arn:aws:iam::975050371175:role/github-sa-role
# role-session-name: githubsa
# - name: Setup Profile
# run: |
# aws configure set region ${{ env.AWS_REGION }} --profile githubsa
# aws configure set aws_access_key_id ${{ env.AWS_ACCESS_KEY_ID }} --profile githubsa
# aws configure set aws_secret_access_key ${{ env.AWS_SECRET_ACCESS_KEY }} --profile githubsa
# aws configure set aws_session_token ${{ env.AWS_SESSION_TOKEN }} --profile githubsa
- name: Retrieve envs from AWS Secrets Manager 1
working-directory: packages/core-mobile/scripts/github
env:
AWS_PROFILE: 'test'
AWS_DEFAULT_PROFILE: 'test'
run: |
sudo cat ~/.aws/config
sudo echo output = json >> ~/.aws/config
sudo cat ~/.aws/config
sudo aws secretsmanager list-secrets
# sudo aws --profile test secretsmanager get-secret-value --secret-id core/dev/mobile/.env.development.test | grep "SecretString"
# - name: Retrieve envs from AWS Secrets Manager 2
# working-directory: packages/core-mobile/scripts/github
# run: |
# aws secretsmanager get-secret-value --secret-id "core/dev/mobile/.env.development.test" | grep "SecretString"
# - name: Retrieve envs from AWS Secrets Manager
# working-directory: packages/core-mobile/scripts/github
# run: |
# ./fetchEnvsFromAWS.sh "core/dev/mobile/.env.development.test" ".env.test"
# cat .env.test