!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

657 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues166 Servers

Load older messages


SenderMessageTime
16 Mar 2023
@joerg:thalheim.ioMic92But maybe this was just for github merges...13:39:17
@brian:bmcgee.ie@brian:bmcgee.ieif it can, even better. Simplifies things13:39:17
@brian:bmcgee.ie@brian:bmcgee.ieFor now it looks like I need to generate a gpg key and add it to a bot github profile13:39:39
@brian:bmcgee.ie@brian:bmcgee.iefrom what I'm googling13:39:45
@joerg:thalheim.ioMic92https://github.com/Nautilus-Cyberneering/pygithub/blob/main/docs/how_to_sign_automatic_commits_in_github_actions.md#solution-01-using-the-temporary-github_token-generated-for-each-workflow-job13:39:51
@joerg:thalheim.ioMic92Looks like you need to have a gpg key.13:40:22
@joerg:thalheim.ioMic92I don't think you need a bot account however.13:40:30
@joerg:thalheim.ioMic92Ok. Maybe to assign it an identity...13:40:57
@brian:bmcgee.ie@brian:bmcgee.ieYeah looks like13:41:26
@joerg:thalheim.ioMic92I guess if you want to get the green mark than an account is required.13:41:44
@brian:bmcgee.ie@brian:bmcgee.ieWhich is why I figure it makes sense to have a nix-community bot profile rather than creating one for each repo potentially13:41:48
@brian:bmcgee.ie@brian:bmcgee.iewith an org wide bot gpg key that can be dropped in if you need signed commits13:42:08
@joerg:thalheim.ioMic92Well, than this bot also would need to be a contributor potentially. But maybe not.13:42:20
@joerg:thalheim.ioMic92If we had to give than each repo also a github token, this would be not so nice from a security perspective since than every user could potentially use this. But I guess this might be not needed.13:43:01
@joerg:thalheim.ioMic92We would only have per project gpg keys13:43:45
@brian:bmcgee.ie@brian:bmcgee.ieI think that makes sense. Isolates the key to a project, but a common github profile for the bot13:44:24
@brian:bmcgee.ie@brian:bmcgee.ieif you need a key ask an admin to drop in a new gpg key on the bot account and then add that as a repo secret13:44:48
@brian:bmcgee.ie@brian:bmcgee.ie?13:44:57
@joerg:thalheim.ioMic92I would probably automate this away with the terraform github provider.13:45:34
@joerg:thalheim.ioMic92if this is a feature there.13:45:44
@joerg:thalheim.ioMic92so that people would make a PR.13:45:54
@brian:bmcgee.ie@brian:bmcgee.ieeven better13:46:04
@joerg:thalheim.ioMic92https://registry.terraform.io/providers/integrations/github/latest/docs/resources/user_gpg_key13:46:17
@joerg:thalheim.ioMic92That' looks easy enough.13:46:27
@joerg:thalheim.ioMic92make an issue here please: https://github.com/nix-community/infra/issues13:46:49
@brian:bmcgee.ie@brian:bmcgee.ieis there already a terraform setup for managing nix-community infra?13:46:51
@brian:bmcgee.ie@brian:bmcgee.ieAh cool13:46:54
@joerg:thalheim.ioMic92yes, we have that for dns stuff13:47:03
@brian:bmcgee.ie@brian:bmcgee.iehttps://github.com/nix-community/infra/issues/48213:53:18
@joerg:thalheim.ioMic92 BMG: mhm. One issue still. When we have one bot with multiple private keys than each private key would be still recognized as valid... 13:56:09

Show newer messages


Back to Room ListRoom Version: 6