GitHub workflow fails to run when code is pushed into branch

Viewed 219

A CI/CD pipeline in GitHub needs to first push code from the dev branch to the test branch, and then immediately run a workflow on the test branch as soon as code has been pushed into the test branch.

The dev-environ-workflow below does successfully push code from the dev branch into the test branch when code is pushed into the dev branch from a devbox outside of GitHub.

The problem is that the test-environ-workflow fails to run when code is pushed into the test branch from the dev-environ-workflow.

Any GitHub account can reproduce this problem with only three files and the following structure:

.gihub/workflows/
    dev-workflow.yaml
    test-workflow.yaml
myapp.py

myapp.py:

print('Hello from myapp!')

dev-workflow.yaml:

name: dev-environ-workflow
on:
  push:
    branches:
      - dev
jobs:
  push-to-test-branch:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - shell: bash
        name: Push changes to test branch
        env:
          GIT_PAT: ${{ secrets.GIT_PAT }}
        run: |
          repoWithToken="https://"$GIT_PAT"@github.com/myAccountName/trigger.git"
          git config --global user.email "me@mydomain.com"
          git config --global user.name "myAccountName"
          git init
          git remote set-url origin $repoWithToken
          git branch -M test
          git add --all
          git push --force -u origin test

test-workflow.yaml:

name: test-environ-workflow
on:
  push:
    branches:
      - test
jobs:
  push-to-test-branch:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - shell: bash
        name: Do anything
        run: echo "Successfully triggered test-environ-workflow"

The commands to trigger the dev-environ-workflow from a remote devbox anywhere on the internet outside of GitHub are:

git init
git add --all
git commit -m "some changes"
git branch -M dev
git push -u origin dev

You also need to create an environment variable for the GitHub repository called GIT_PAT which contains a personal access token that will be used to push code into the test branch.

What specifically needs to change in the above in order for the test-environ-workflow to be successfully triggered whenever the dev-environ-workflow successfully pushes code into the test branch?

1 Answers

As you probably know from the GitHub docs:

When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN, with the exception of workflow_dispatch and repository_dispatch, will not create a new workflow run. This prevents you from accidentally creating recursive workflow runs.

You're using a Personal Access Token to get around this issue, but actions/checkout stores the GITHUB_TOKEN in the local repo config anyways and will use that instead of your PAT when performing git operations.

That is documented in the actions/checkout README file

The auth token is persisted in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup. Set persist-credentials: false to opt-out.

You need to tell actions/checkout to not persist the token using persist-credentials: false.

So the uses step in your dev workflow becomes this:

steps:
  - uses: actions/checkout@v3
    with:
      persist-credentials: false
  - more steps...

UPDATE

@GuiFalourd mentioned in the question comments that you may just need to override the GITHUB_TOKEN environment variable. I actually like that solution better because then you don't have to pass the token in the repo URL, meaning you don't have to override the repo remote at all. I'm not actually overriding the GITHUB_TOKEN environment variable here, but you can pass your PAT to actions/checkout instead.

steps:
  - uses: actions/checkout@v3
    with:
      token: ${{ secrets.GIT_PAT }}
  - more steps...

Here is my minimal working version of your dev workflow:

Changes:

  • You don't need to initialize the repo because actions/checkout has already done that.
  • You don't need to change the remote URL anymore because we're not passing the token in the URL.
  • You don't need to git add --all because you're not changing any files.
  • You don't need to set the user name or email because you're not creating any new commits.
  • You don't have to change or rename your branch to test. You can push the currently checked out HEAD commit to any remote branch by name.
name: dev-environ-workflow
on:
  push:
    branches:
      - dev
jobs:
  push-to-test-branch:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
        with:
          token: ${{ secrets.GIT_PAT }}
      - shell: bash
        name: Push changes to test branch
        run: git push -f origin HEAD:test
Related