mirror of
https://github.com/whekin/household-bot.git
synced 2026-03-31 17:54:02 +00:00
fix(cd): simplify webhook secret loading and add error checking
This commit is contained in:
25
.github/workflows/cd.yml
vendored
25
.github/workflows/cd.yml
vendored
@@ -230,35 +230,30 @@ jobs:
|
|||||||
- name: Load webhook secret
|
- name: Load webhook secret
|
||||||
id: webhook-secret
|
id: webhook-secret
|
||||||
run: |
|
run: |
|
||||||
set +e
|
|
||||||
secret_name="telegram-webhook-secret"
|
secret_name="telegram-webhook-secret"
|
||||||
if [[ "${SERVICE_SUFFIX}" == "dev" ]]; then
|
if [[ "${SERVICE_SUFFIX}" == "dev" ]]; then
|
||||||
secret_name="telegram-webhook-secret-test"
|
secret_name="telegram-webhook-secret-test"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
echo "Loading secret: ${secret_name}"
|
||||||
secret="$(gcloud secrets versions access latest \
|
secret="$(gcloud secrets versions access latest \
|
||||||
--secret "${secret_name}" \
|
--secret "${secret_name}" \
|
||||||
--project "${{ vars.GCP_PROJECT_ID }}" 2>/dev/null)"
|
--project "${{ vars.GCP_PROJECT_ID }}")"
|
||||||
status=$?
|
|
||||||
set -e
|
|
||||||
|
|
||||||
if [[ $status -eq 0 && -n "$secret" ]]; then
|
|
||||||
echo "::add-mask::$secret"
|
echo "::add-mask::$secret"
|
||||||
{
|
echo "secret=${secret}" >> "$GITHUB_OUTPUT"
|
||||||
echo "available=true"
|
|
||||||
echo "secret<<EOF"
|
|
||||||
echo "$secret"
|
|
||||||
echo "EOF"
|
|
||||||
} >> "$GITHUB_OUTPUT"
|
|
||||||
else
|
|
||||||
echo "available=false" >> "$GITHUB_OUTPUT"
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Set Telegram Webhook
|
- name: Set Telegram Webhook
|
||||||
if: ${{ steps.telegram-token.outputs.available == 'true' && steps.webhook-secret.outputs.available == 'true' }}
|
if: ${{ !cancelled() && steps.telegram-token.outputs.available == 'true' }}
|
||||||
env:
|
env:
|
||||||
TELEGRAM_BOT_TOKEN: ${{ steps.telegram-token.outputs.token }}
|
TELEGRAM_BOT_TOKEN: ${{ steps.telegram-token.outputs.token }}
|
||||||
TELEGRAM_WEBHOOK_SECRET: ${{ steps.webhook-secret.outputs.secret }}
|
TELEGRAM_WEBHOOK_SECRET: ${{ steps.webhook-secret.outputs.secret }}
|
||||||
run: |
|
run: |
|
||||||
|
if [[ -z "$TELEGRAM_WEBHOOK_SECRET" ]]; then
|
||||||
|
echo "ERROR: TELEGRAM_WEBHOOK_SECRET is not set"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
SERVICE_URL=$(gcloud run services describe "household-${SERVICE_SUFFIX}-bot-api" \
|
SERVICE_URL=$(gcloud run services describe "household-${SERVICE_SUFFIX}-bot-api" \
|
||||||
--region "${GCP_REGION}" \
|
--region "${GCP_REGION}" \
|
||||||
--project "${{ vars.GCP_PROJECT_ID }}" \
|
--project "${{ vars.GCP_PROJECT_ID }}" \
|
||||||
|
|||||||
Reference in New Issue
Block a user