Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,27 @@ These badges show the status of workflows in dummy repositories that use (or sho
- [`check-sca`](#check-sca)
- [`update-release-channel`](#update-release-channel)
- [`report-ci-metrics`](#report-ci-metrics)
- [`wait-for-artifactory-token-federation`](#wait-for-artifactory-token-federation)

---

## `wait-for-artifactory-token-federation`

Wait for a Vault-issued Artifactory token to become usable on the JFrog Edge node before downloading Orchestrator artifacts.
Set `ARTIFACTORY_ACCESS_TOKEN` in a prior step and use an authenticated path that the token can read. The action retries
temporary HTTP and connection failures, then fails after 12 attempts. It requires a runner that can reach the Edge node;
GitHub-hosted runners currently cannot reach the default internal host.

```yaml
- uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4
with:
probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*"
```

| Input | Description | Default |
Comment on lines +68 to +85

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: README section order doesn't match the table of contents

The new entry is added at the end of the "Actions provided in this repository" list, after report-ci-metrics. The ## wait-for-artifactory-token-federation section, however, sits right after that list and before ## get-build-number (line 89). Every other README section follows the list order, so a reader expecting this action last will find it first. To fix this, move the section (and its --- separator) to just after the report-ci-metrics section and before ## Deployment Strategy, or move the list entry to the top of the list.

Was this helpful? React with 👍 / 👎

| --- | --- | --- |
| `artifactory-url` | Artifactory base URL on the Edge node | `https://repox-internal.dev.sonar.build/artifactory` |
| `probe-path` | Readable path relative to the Artifactory base URL | Required |

---

Expand Down
41 changes: 41 additions & 0 deletions wait-for-artifactory-token-federation/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: Wait for Artifactory token federation
description: Wait until a Vault-issued Artifactory token is accepted by the JFrog Edge node

inputs:
artifactory-url:
description: JFrog Artifactory base URL
default: https://repox-internal.dev.sonar.build/artifactory
probe-path:
description: Authenticated Edge endpoint path and optional query used to verify the token
required: true

runs:
using: composite
steps:
- shell: bash
env:
ARTIFACTORY_URL: ${{ inputs.artifactory-url }}
PROBE_PATH: ${{ inputs.probe-path }}
run: |
: "${ARTIFACTORY_ACCESS_TOKEN:?ARTIFACTORY_ACCESS_TOKEN must be configured before waiting for token federation}"

for attempt in {1..12}; do
status=$(curl --silent --show-error --connect-timeout 5 --max-time 10 --output /dev/null --write-out "%{http_code}" \
--header "Authorization: Bearer ${ARTIFACTORY_ACCESS_TOKEN}" \
"${ARTIFACTORY_URL}/${PROBE_PATH}" || true)
if [[ "${status}" == "200" ]]; then
echo "Artifactory token accepted by Edge"
exit 0
fi
if [[ ! "${status}" =~ ^(000|401|408|429|500|502|503|504)$ ]]; then
echo "Unexpected response from Edge: HTTP ${status}"
exit 1
fi
echo "Waiting for Artifactory token federation (attempt ${attempt}/12, HTTP ${status})"
if (( attempt < 12 )); then
sleep 10
fi
done

echo "Artifactory token was not accepted by Edge after 12 attempts"
exit 1
Loading