ci: pass the registry password on stdin, fail on a failed push
Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 44s
Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 44s
A password in argv is world-readable through /proc/PID/cmdline while the command runs; docker warns about it for that reason. The environment of a process is readable by its owner alone, so $PASS itself was never the problem. The two pushes are joined with && rather than left as separate statements: the step's exit code is the last command's, so the intent is now explicit instead of resting on whatever -e flag the runner's shell happens to carry.
This commit is contained in:
@@ -31,9 +31,9 @@ jobs:
|
||||
--tag "${REGISTRY}/${REPOSITORY##*/}:latest"
|
||||
- name: Docker login
|
||||
run: |
|
||||
docker login --username "$USER" --password "$PASS" "$REGISTRY"
|
||||
echo "$PASS" | docker login --username "$USER" --password-stdin "$REGISTRY"
|
||||
- name: Push images to registry
|
||||
run: |
|
||||
docker push "${REGISTRY}/${REPOSITORY##*/}:${VERSION}.${COMMIT::7}" ; \
|
||||
docker push "${REGISTRY}/${REPOSITORY##*/}:${VERSION}.${COMMIT::7}" && \
|
||||
docker push "${REGISTRY}/${REPOSITORY##*/}:latest"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user