Spring Cloud Config with Github repo using Credentials

Viewed 1883

I am trying to access the Github repo which sits behind an enterprise firewall (Open VPN). I am trying to access with my username and password but getting the below Exception. Any suggestions on how to access the repo with Spring Cloud.

application.properties:

spring.cloud.config.server.git.uri=https://github.com/company-repo/abc.git
spring.cloud.config.server.git.username=tarun
spring.cloud.config.server.git.password=xxxxx
spring.cloud.config.server.git.ignore-local-ssh-settings=true

Exception:

Error occured cloning to base directory. org.eclipse.jgit.api.errors.TransportException:
 https://github.com/company-repo/abc.git: not authorized
2 Answers

Do not Use Your GitHub password in your app.prop file...You will get a Not Authorized exception. Instead Generate an access token.

Creating a personal access token

You should create a personal access token to use in place of a password with the command line or with the API.

Personal access tokens (PATs) are an alternative to using passwords for authentication to GitHub when using the GitHub API or the command line.

If you want to use a PAT to access resources owned by an organization that uses SAML SSO, you must authorize the PAT. For more information, see "About authentication with SAML single sign-on" and "Authorizing a personal access token for use with SAML single sign-on."

As a security precaution, GitHub automatically removes personal access tokens that haven't been used in a year.

Creating a token

  • Verify your email address, if it hasn't been verified yet.

  • In the upper-right corner of any page, click your profile photo, then click Settings.

  • Settings icon in the user bar In the left sidebar, click Developer settings.

  • In the left sidebar, click Personal access tokens.

  • Click Generate new token.

  • Give your token a descriptive name.

  • Select the scopes, or permissions, you'd like to grant this token. To use your token to access repositories from the command line, select repo.

  • Click Generate token.

  • Click to copy the token to your clipboard. For security reasons, after you navigate off the page, you will not be able to see the token again.

Warning: Treat your tokens like passwords and keep them secret. When working with the API, use tokens as environment variables instead of hardcoding them into your programs.

To use your token to authenticate to an organization that uses SAML SSO, authorize the token for use with a SAML single-sign-on organization.

Using a token on the command line

Once you have a token, you can enter it instead of your password when performing Git operations over HTTPS.

For example, on the command line you would enter the following:

$ git clone https://github.com/username/repo.git
Username: your_username
Password: your_token

Personal access tokens can only be used for HTTPS Git operations. If your repository uses an SSH remote URL, you will need to switch the remote from SSH to HTTPS.

If you are not prompted for your username and password, your credentials may be cached on your computer. You can update your credentials in the Keychain to replace your old password with the token.

The way i made it work is :

  1. Generate the Access Token on Github repo and provide read and admin rights to it
  2. Use the Token as password

Credentials can be saved in Kubernetes as Secrets or inside Vault. Hope this helps.

Related