1313 # 🖊️ EDIT to change the image registry settings.
1414
1515 # Vars
16- ROX_CENTRAL_ENDPOINT : ${{ vars.ROX_CENTRAL_ENDPOINT }}
17- # GITOPS_AUTH_USERNAME: ${{ vars.GITOPS_AUTH_USERNAME }}
16+ ROX_CENTRAL_ENDPOINT : ${{ '${{' }} vars.ROX_CENTRAL_ENDPOINT }}
17+ # GITOPS_AUTH_USERNAME: ${{ '${{' }} vars.GITOPS_AUTH_USERNAME }}
1818 # Set this to the user for your specific registry
19- IMAGE_REGISTRY_USER : ${{ vars.IMAGE_REGISTRY_USER }}
19+ IMAGE_REGISTRY_USER : ${{ '${{' }} vars.IMAGE_REGISTRY_USER }}
2020 # Set this only when using an external Rekor instance
21- REKOR_HOST : ${{ vars.REKOR_HOST }}
21+ REKOR_HOST : ${{ '${{' }} vars.REKOR_HOST }}
2222 # Set this only when using an external TUF instance
23- TUF_MIRROR : ${{ vars.TUF_MIRROR }}
24- # QUAY_IO_CREDS_USR: ${{ vars.QUAY_IO_CREDS_USR }}
25- # ARTIFACTORY_IO_CREDS_USR: ${{ vars.ARTIFACTORY_IO_CREDS_USR }}
26- # NEXUS_IO_CREDS_USR: ${{ vars.NEXUS_IO_CREDS_USR }}
23+ TUF_MIRROR : ${{ '${{' }} vars.TUF_MIRROR }}
24+ # QUAY_IO_CREDS_USR: ${{ '${{' }} vars.QUAY_IO_CREDS_USR }}
25+ # ARTIFACTORY_IO_CREDS_USR: ${{ '${{' }} vars.ARTIFACTORY_IO_CREDS_USR }}
26+ # NEXUS_IO_CREDS_USR: ${{ '${{' }} vars.NEXUS_IO_CREDS_USR }}
2727 # Used to verify the image signature and attestation
28- COSIGN_PUBLIC_KEY : ${{ vars.COSIGN_PUBLIC_KEY }}
28+ COSIGN_PUBLIC_KEY : ${{ '${{' }} vars.COSIGN_PUBLIC_KEY }}
2929 # Custom Root CA to be used in scripts as trusted
30- CUSTOM_ROOT_CA : ${{ vars.CUSTOM_ROOT_CA }}
30+ CUSTOM_ROOT_CA : ${{ '${{' }} vars.CUSTOM_ROOT_CA }}
3131 # Secrets
32- ROX_API_TOKEN : ${{ secrets.ROX_API_TOKEN }}
33- GITOPS_AUTH_PASSWORD : ${{ secrets.GITOPS_AUTH_PASSWORD }}
32+ ROX_API_TOKEN : ${{ '${{' }} secrets.ROX_API_TOKEN }}
33+ GITOPS_AUTH_PASSWORD : ${{ '${{' }} secrets.GITOPS_AUTH_PASSWORD }}
3434 # Set this password for your specific registry
35- IMAGE_REGISTRY_PASSWORD : ${{ secrets.IMAGE_REGISTRY_PASSWORD }}
36- # QUAY_IO_CREDS_PSW: ${{ secrets.QUAY_IO_CREDS_PSW }}
37- # ARTIFACTORY_IO_CREDS_PSW: ${{ secrets.ARTIFACTORY_IO_CREDS_PSW }}
38- # NEXUS_IO_CREDS_PSW: ${{ secrets.NEXUS_IO_CREDS_PSW }}
39- COSIGN_SECRET_PASSWORD : ${{ secrets.COSIGN_SECRET_PASSWORD }}
40- COSIGN_SECRET_KEY : ${{ secrets.COSIGN_SECRET_KEY }}
35+ IMAGE_REGISTRY_PASSWORD : ${{ '${{' }} secrets.IMAGE_REGISTRY_PASSWORD }}
36+ # QUAY_IO_CREDS_PSW: ${{ '${{' }} secrets.QUAY_IO_CREDS_PSW }}
37+ # ARTIFACTORY_IO_CREDS_PSW: ${{ '${{' }} secrets.ARTIFACTORY_IO_CREDS_PSW }}
38+ # NEXUS_IO_CREDS_PSW: ${{ '${{' }} secrets.NEXUS_IO_CREDS_PSW }}
39+ COSIGN_SECRET_PASSWORD : ${{ '${{' }} secrets.COSIGN_SECRET_PASSWORD }}
40+ COSIGN_SECRET_KEY : ${{ '${{' }} secrets.COSIGN_SECRET_KEY }}
4141
4242 # Registries such as GHCR, Quay.io, and Docker Hub are supported.
43- IMAGE_REGISTRY : ${{ secrets.IMAGE_REGISTRY }}
43+ IMAGE_REGISTRY : ${{ '${{' }} secrets.IMAGE_REGISTRY }}
4444
4545 # 🖊️ EDIT to specify custom tags for the container image, or default tags will be generated below.
4646 IMAGE_TAGS : " "
5151on :
5252 push :
5353 branches :
54- - ' main'
54+ - " main"
5555 workflow_dispatch :
5656
5757jobs :
@@ -69,21 +69,21 @@ jobs:
6969 with :
7070 script : |
7171 const vars = {
72- IMAGE_REGISTRY: `${{ vars.IMAGE_REGISTRY }}`,
72+ IMAGE_REGISTRY: `${{ '${{' }} vars.IMAGE_REGISTRY }}`,
7373
74- ROX_CENTRAL_ENDPOINT: `${{ vars.ROX_CENTRAL_ENDPOINT }}`,
75- /* GITOPS_AUTH_USERNAME: `${{ vars.GITOPS_AUTH_USERNAME }}`, */
74+ ROX_CENTRAL_ENDPOINT: `${{ '${{' }} vars.ROX_CENTRAL_ENDPOINT }}`,
75+ /* GITOPS_AUTH_USERNAME: `${{ '${{' }} vars.GITOPS_AUTH_USERNAME }}`, */
7676 /* Set this to the user for your specific registry */
77- IMAGE_REGISTRY_USER: `${{ vars.IMAGE_REGISTRY_USER }}`,
77+ IMAGE_REGISTRY_USER: `${{ '${{' }} vars.IMAGE_REGISTRY_USER }}`,
7878 /* Set this only when using an external Rekor instance */
79- REKOR_HOST: `${{ vars.REKOR_HOST }}`,
79+ REKOR_HOST: `${{ '${{' }} vars.REKOR_HOST }}`,
8080 /* Set this only when using an external TUF instance */
81- TUF_MIRROR: `${{ vars.TUF_MIRROR }}`,
82- /* QUAY_IO_CREDS_USR: `${{ vars.QUAY_IO_CREDS_USR }}`, */
83- /* ARTIFACTORY_IO_CREDS_USR: `${{ vars.ARTIFACTORY_IO_CREDS_USR }}`, */
84- /* NEXUS_IO_CREDS_USR: `${{ vars.NEXUS_IO_CREDS_USR }}`, */
81+ TUF_MIRROR: `${{ '${{' }} vars.TUF_MIRROR }}`,
82+ /* QUAY_IO_CREDS_USR: `${{ '${{' }} vars.QUAY_IO_CREDS_USR }}`, */
83+ /* ARTIFACTORY_IO_CREDS_USR: `${{ '${{' }} vars.ARTIFACTORY_IO_CREDS_USR }}`, */
84+ /* NEXUS_IO_CREDS_USR: `${{ '${{' }} vars.NEXUS_IO_CREDS_USR }}`, */
8585 /* Used to verify the image signature and attestation */
86- COSIGN_PUBLIC_KEY: `${{ vars.COSIGN_PUBLIC_KEY }}`,
86+ COSIGN_PUBLIC_KEY: `${{ '${{' }} vars.COSIGN_PUBLIC_KEY }}`,
8787 };
8888
8989 const missingVars = Object.entries(vars).filter(([ name, value ]) => {
@@ -97,15 +97,15 @@ jobs:
9797
9898 const secrets = {
9999
100- ROX_API_TOKEN: `${{ secrets.ROX_API_TOKEN }}`,
101- GITOPS_AUTH_PASSWORD: `${{ secrets.GITOPS_AUTH_PASSWORD }}`,
100+ ROX_API_TOKEN: `${{ '${{' }} secrets.ROX_API_TOKEN }}`,
101+ GITOPS_AUTH_PASSWORD: `${{ '${{' }} secrets.GITOPS_AUTH_PASSWORD }}`,
102102 /* Set this password for your specific registry */
103- IMAGE_REGISTRY_PASSWORD: `${{ secrets.IMAGE_REGISTRY_PASSWORD }}`,
104- /* QUAY_IO_CREDS_PSW: `${{ secrets.QUAY_IO_CREDS_PSW }}`, */
105- /* ARTIFACTORY_IO_CREDS_PSW: `${{ secrets.ARTIFACTORY_IO_CREDS_PSW }}`, */
106- /* NEXUS_IO_CREDS_PSW: `${{ secrets.NEXUS_IO_CREDS_PSW }}`, */
107- COSIGN_SECRET_PASSWORD: `${{ secrets.COSIGN_SECRET_PASSWORD }}`,
108- COSIGN_SECRET_KEY: `${{ secrets.COSIGN_SECRET_KEY }}`,
103+ IMAGE_REGISTRY_PASSWORD: `${{ '${{' }} secrets.IMAGE_REGISTRY_PASSWORD }}`,
104+ /* QUAY_IO_CREDS_PSW: `${{ '${{' }} secrets.QUAY_IO_CREDS_PSW }}`, */
105+ /* ARTIFACTORY_IO_CREDS_PSW: `${{ '${{' }} secrets.ARTIFACTORY_IO_CREDS_PSW }}`, */
106+ /* NEXUS_IO_CREDS_PSW: `${{ '${{' }} secrets.NEXUS_IO_CREDS_PSW }}`, */
107+ COSIGN_SECRET_PASSWORD: `${{ '${{' }} secrets.COSIGN_SECRET_PASSWORD }}`,
108+ COSIGN_SECRET_KEY: `${{ '${{' }} secrets.COSIGN_SECRET_KEY }}`,
109109 };
110110
111111 const missingSecrets = Object.entries(secrets).filter(([ name, value ]) => {
@@ -141,7 +141,7 @@ jobs:
141141 - name : Check out repository
142142 uses : actions/checkout@v4
143143 with :
144- fetch-depth : ' 2 '
144+ fetch-depth : " 2 "
145145 - name : Pre-init
146146 run : |
147147 buildah --version
0 commit comments