Skip to content

PREQ-9016 Add public shared action for JFrog Edge token federation - #353

Open
guillaume-dequenne wants to merge 2 commits into
masterfrom
CLP-918
Open

guillaume-dequenne wants to merge 2 commits into
masterfrom
CLP-918

Conversation

@guillaume-dequenne

@guillaume-dequenne guillaume-dequenne commented Sep 29, 2026 •

Copy link
Copy Markdown

Part of CLP-918

Why this action is needed

sonar-java #6257 is a concrete consumer: its public workflow cannot load the existing action from the private sonarsource-infra-artifactory repository. Putting the token federation wait in this public shared-actions repository removes the local helper copies from public migration PRs.

The action waits for a Vault-issued token to be accepted by JFrog Edge before an Orchestrator download. It retries temporary Edge responses, including 503, and documents the runner and token requirements.

Dependent PRs

Each currently pins the action commit from this branch and references this PR in its description. Merge this PR first; then repin the consumers to a retained commit or release tag before merging them. The private migration PRs use the existing shared private action and do not depend on this PR.

@guillaume-dequenne
guillaume-dequenne requested a review from a team as a code owner September 29, 2026 08:39
@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Migrate Orchestrator downloads to the JFrog Edge node for ci-github-actions PREQ-9016 Migrate Orchestrator downloads to the JFrog Edge node for ci-github-actions Sep 29, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

PREQ-9016

@gitar-bot

gitar-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Reviewing your code

Code Review 👍 Approved with suggestions 0 closed / 1 findings

🟡 Medium risk · Adds bounded token-readiness retries before artifact downloads, changing CI execution behavior.

Adds the wait-for-artifactory-token-federation action to handle temporary Edge failures before Orchestrator downloads, with comprehensive runner and token documentation. The README section order doesn't match the table of contents—move the new section to follow report-ci-metrics to align with the list ordering used throughout the document.

💡 Quality: README section order doesn't match the table of contents

📄 README.md:68-82

The new entry is added at the end of the "Actions provided in this repository" list, after report-ci-metrics. The ## wait-for-artifactory-token-federation section, however, sits right after that list and before ## get-build-number (line 89). Every other README section follows the list order, so a reader expecting this action last will find it first. To fix this, move the section (and its --- separator) to just after the report-ci-metrics section and before ## Deployment Strategy, or move the list entry to the top of the list.

🤖 Prompt for agents
Code Review: Adds the `wait-for-artifactory-token-federation` action to handle temporary Edge failures before Orchestrator downloads, with comprehensive runner and token documentation. The README section order doesn't match the table of contents—move the new section to follow `report-ci-metrics` to align with the list ordering used throughout the document.

1. 💡 Quality: README section order doesn't match the table of contents
   Files: README.md:68-82

   The new entry is added at the end of the "Actions provided in this repository" list, after `report-ci-metrics`. The `## wait-for-artifactory-token-federation` section, however, sits right after that list and before `## get-build-number` (line 89). Every other README section follows the list order, so a reader expecting this action last will find it first. To fix this, move the section (and its `---` separator) to just after the `report-ci-metrics` section and before `## Deployment Strategy`, or move the list entry to the top of the list.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

Cross-repo coverage 12 repositories selected

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ CLP-918 - 1 of 1 objectives covered

This PR adds the wait-for-artifactory-token-federation action to support migrating Orchestrator downloads to the JFrog Edge node.

✅ 1 covered here
  • ✅ Migrate the Orchestrator's SonarQube download source to the JFrog Edge node
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqubecloud

Copy link
Copy Markdown

Comment thread README.md
Comment on lines +68 to +82
- [`wait-for-artifactory-token-federation`](#wait-for-artifactory-token-federation)

---

## `wait-for-artifactory-token-federation`

Wait for a Vault-issued Artifactory token to become usable on the JFrog Edge node before downloading Orchestrator artifacts. Set `ARTIFACTORY_ACCESS_TOKEN` in a prior step and use an authenticated path that the token can read. The action retries temporary HTTP and connection failures, then fails after 12 attempts. It requires a runner that can reach the Edge node; GitHub-hosted runners currently cannot reach the default internal host.

```yaml
- uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@<full-commit-sha>
with:
probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*"
```

| Input | Description | Default |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: README section order doesn't match the table of contents

The new entry is added at the end of the "Actions provided in this repository" list, after report-ci-metrics. The ## wait-for-artifactory-token-federation section, however, sits right after that list and before ## get-build-number (line 89). Every other README section follows the list order, so a reader expecting this action last will find it first. To fix this, move the section (and its --- separator) to just after the report-ci-metrics section and before ## Deployment Strategy, or move the list entry to the top of the list.

Was this helpful? React with 👍 / 👎

@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant