Skip to content

Commit 75207c8

Browse files
authored
Use ephemeral github token for build. (#712)
The `VAULT_GITHUB_TOKEN` env var contains the token with permissions to create releases. Goreleaser on the other hand will only use `GITHUB_TOKEN` for the release.
1 parent 7dd5d83 commit 75207c8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.buildkite/hooks/pre-command

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,5 +12,5 @@ if [[ "$BUILDKITE_PIPELINE_SLUG" == "terraform-provider-elasticstack-release" ]]
1212
export GPG_PRIVATE_SECRET=$(scripts/retry.sh 5 vault kv get -field gpg_private ${RELEASE_VAULT_PATH})
1313
export GPG_PASSPHRASE_SECRET=$(scripts/retry.sh 5 vault kv get -field gpg_passphrase ${RELEASE_VAULT_PATH})
1414
export GPG_FINGERPRINT_SECRET=$(scripts/retry.sh 5 vault kv get -field gpg_fingerprint ${RELEASE_VAULT_PATH})
15-
export GITHUB_TOKEN=$(scripts/retry.sh 5 vault kv get -field gh_personal_access_token ${RELEASE_VAULT_PATH})
15+
export GITHUB_TOKEN="${VAULT_GITHUB_TOKEN}"
1616
fi

0 commit comments

Comments
 (0)