Skip to content

Commit 803c64f

Browse files
authored
fix(ci): add correcting signing keys for ci and release process on 1.x (#1027)
1 parent 379d9e7 commit 803c64f

File tree

3 files changed

+9
-9
lines changed

3 files changed

+9
-9
lines changed

codebuild/ci/release-ci.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ env:
1212
parameter-store:
1313
ACCOUNT: /CodeBuild/AccountIdentity
1414
secrets-manager:
15-
GPG_KEY: Maven-GPG-Keys-Credentials:Keyname
16-
GPG_PASS: Maven-GPG-Keys-Credentials:Passphrase
15+
GPG_KEY: Maven-GPG-Keys-CI-Credentials:Keyname
16+
GPG_PASS: Maven-GPG-Keys-CI-Credentials:Passphrase
1717

1818
phases:
1919
install:
@@ -24,7 +24,7 @@ phases:
2424
- export SETTINGS_FILE=$(pwd)/codebuild/release/settings.xml
2525
- export CODEARTIFACT_TOKEN=$(aws codeartifact get-authorization-token --domain $DOMAIN --domain-owner $ACCOUNT --query authorizationToken --output text --region ${REGION})
2626
- export CODEARTIFACT_REPO_URL=https://${DOMAIN}-${ACCOUNT}.d.codeartifact.${REGION}.amazonaws.com/maven/${REPOSITORY}
27-
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
27+
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys-CI --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
2828
- tar -xvf ~/mvn_gpg.tgz -C ~
2929
build:
3030
commands:

codebuild/release/release-prod.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,8 @@ env:
77
variables:
88
BRANCH: "mainline-1.x"
99
secrets-manager:
10-
GPG_KEY: Maven-GPG-Keys-Credentials:Keyname
11-
GPG_PASS: Maven-GPG-Keys-Credentials:Passphrase
10+
GPG_KEY: Maven-GPG-Keys-Release-Credentials:Keyname
11+
GPG_PASS: Maven-GPG-Keys-Release-Credentials:Passphrase
1212
SONA_USERNAME: Sonatype-Team-Account:Username
1313
SONA_PASSWORD: Sonatype-Team-Account:Password
1414

@@ -21,7 +21,7 @@ phases:
2121
- git checkout $BRANCH
2222
- export VERSION=$(grep version pom.xml | head -n 1 | sed -n 's/[ \t]*<version>\(.*\)<\/version>/\1/p')
2323
- export SETTINGS_FILE=$(pwd)/codebuild/release/settings.xml
24-
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
24+
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys-Release --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
2525
- tar -xvf ~/mvn_gpg.tgz -C ~
2626
build:
2727
commands:

codebuild/release/release-staging.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ env:
1212
parameter-store:
1313
ACCOUNT: /CodeBuild/AccountId
1414
secrets-manager:
15-
GPG_KEY: Maven-GPG-Keys-Credentials:Keyname
16-
GPG_PASS: Maven-GPG-Keys-Credentials:Passphrase
15+
GPG_KEY: Maven-GPG-Keys-Release-Credentials:Keyname
16+
GPG_PASS: Maven-GPG-Keys-Release-Credentials:Passphrase
1717

1818
phases:
1919
install:
@@ -25,7 +25,7 @@ phases:
2525
- export SETTINGS_FILE=$(pwd)/codebuild/release/settings.xml
2626
- export CODEARTIFACT_TOKEN=$(aws codeartifact get-authorization-token --domain $DOMAIN --domain-owner $ACCOUNT --query authorizationToken --output text --region ${REGION})
2727
- export CODEARTIFACT_REPO_URL=https://${DOMAIN}-${ACCOUNT}.d.codeartifact.${REGION}.amazonaws.com/maven/${REPOSITORY}
28-
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
28+
- aws secretsmanager get-secret-value --region us-west-2 --secret-id Maven-GPG-Keys-Release --query SecretBinary --output text | base64 -d > ~/mvn_gpg.tgz
2929
- tar -xvf ~/mvn_gpg.tgz -C ~
3030
build:
3131
commands:

0 commit comments

Comments
 (0)