diff --git a/README.md b/README.md index 90864329..d0fb8e05 100644 --- a/README.md +++ b/README.md @@ -65,6 +65,27 @@ These badges show the status of workflows in dummy repositories that use (or sho - [`check-sca`](#check-sca) - [`update-release-channel`](#update-release-channel) - [`report-ci-metrics`](#report-ci-metrics) +- [`wait-for-artifactory-token-federation`](#wait-for-artifactory-token-federation) + +--- + +## `wait-for-artifactory-token-federation` + +Wait for a Vault-issued Artifactory token to become usable on the JFrog Edge node before downloading Orchestrator artifacts. +Set `ARTIFACTORY_ACCESS_TOKEN` in a prior step and use an authenticated path that the token can read. The action retries +temporary HTTP and connection failures, then fails after 12 attempts. It requires a runner that can reach the Edge node; +GitHub-hosted runners currently cannot reach the default internal host. + +```yaml +- uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4 + with: + probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" +``` + +| Input | Description | Default | +| --- | --- | --- | +| `artifactory-url` | Artifactory base URL on the Edge node | `https://repox-internal.dev.sonar.build/artifactory` | +| `probe-path` | Readable path relative to the Artifactory base URL | Required | --- diff --git a/wait-for-artifactory-token-federation/action.yml b/wait-for-artifactory-token-federation/action.yml new file mode 100644 index 00000000..776840ec --- /dev/null +++ b/wait-for-artifactory-token-federation/action.yml @@ -0,0 +1,41 @@ +name: Wait for Artifactory token federation +description: Wait until a Vault-issued Artifactory token is accepted by the JFrog Edge node + +inputs: + artifactory-url: + description: JFrog Artifactory base URL + default: https://repox-internal.dev.sonar.build/artifactory + probe-path: + description: Authenticated Edge endpoint path and optional query used to verify the token + required: true + +runs: + using: composite + steps: + - shell: bash + env: + ARTIFACTORY_URL: ${{ inputs.artifactory-url }} + PROBE_PATH: ${{ inputs.probe-path }} + run: | + : "${ARTIFACTORY_ACCESS_TOKEN:?ARTIFACTORY_ACCESS_TOKEN must be configured before waiting for token federation}" + + for attempt in {1..12}; do + status=$(curl --silent --show-error --connect-timeout 5 --max-time 10 --output /dev/null --write-out "%{http_code}" \ + --header "Authorization: Bearer ${ARTIFACTORY_ACCESS_TOKEN}" \ + "${ARTIFACTORY_URL}/${PROBE_PATH}" || true) + if [[ "${status}" == "200" ]]; then + echo "Artifactory token accepted by Edge" + exit 0 + fi + if [[ ! "${status}" =~ ^(000|401|408|429|500|502|503|504)$ ]]; then + echo "Unexpected response from Edge: HTTP ${status}" + exit 1 + fi + echo "Waiting for Artifactory token federation (attempt ${attempt}/12, HTTP ${status})" + if (( attempt < 12 )); then + sleep 10 + fi + done + + echo "Artifactory token was not accepted by Edge after 12 attempts" + exit 1