fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
This commit is contained in:
@@ -84,6 +84,8 @@ jobs:
|
||||
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
||||
|
||||
- name: Build image
|
||||
env:
|
||||
KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }}
|
||||
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
||||
|
||||
- name: Push and sign image
|
||||
|
||||
Reference in New Issue
Block a user