CI integrations
Give a pipeline step its Keepiq secrets in one step, without a secret value in your pipeline configuration. The pipeline holds only your application's private key. Every value is decrypted on the runner.
Both integrations install the keepiq command-line client from a release.
They check the download against the release's SHA256SUMS file and refuse a binary that does not match.
GitHub Actions
Store the application's private key as the repository secret KEEPIQ_APP_KEY. Then:
- uses: ConductionNL/keepiq/integrations/github-action@cli-v0.3.0
with:
url: https://cloud.example.org
application-id: deploy-bot
private-key: ${{ secrets.KEEPIQ_APP_KEY }}
secrets: DB_PASSWORD
run: ./deploy.sh
./deploy.sh finds the value in KEEPIQ_DB_PASSWORD. Nothing is written to disk.
List one secret name per line. Write DB_PASSWORD=PGPASSWORD to choose the variable name yourself.
Exporting to later steps
Set export-env: "true" instead of run when later steps need the values:
- uses: ConductionNL/keepiq/integrations/github-action@cli-v0.3.0
with:
url: https://cloud.example.org
application-id: deploy-bot
private-key: ${{ secrets.KEEPIQ_APP_KEY }}
secrets: API_TOKEN
export-env: "true"
- run: ./publish.sh # sees KEEPIQ_API_TOKEN
Every line of every value is masked in the log first.
Export does write the values to the runner's environment file, so use run when one step is enough.
A step with neither run nor export-env fails and tells you to set one of them.
When you use the action at a branch instead of a cli-v tag, also set version: cli-v0.3.0.
GitLab CI
Include the template at a release tag and extend .keepiq:
include:
- remote: https://raw.githubusercontent.com/ConductionNL/keepiq/cli-v0.3.0/integrations/gitlab-ci/keepiq.gitlab-ci.yml
migrate:
extends: .keepiq
variables:
KEEPIQ_CLI_VERSION: cli-v0.3.0
script:
- keepiq ci run DB_PASSWORD -- ./migrate.sh
Set KEEPIQ_URL, KEEPIQ_APP_ID and KEEPIQ_APP_KEY as protected, masked CI/CD variables.
A variable of type File works too: name it KEEPIQ_APP_KEY_FILE.
./migrate.sh finds the value in KEEPIQ_DB_PASSWORD.
GitLab cannot mask a value fetched during the job, so the template only offers this wrapped form.
The job image needs a shell, curl or wget, and sha256sum.
When the job has its own before_script, start it with - !reference [.keepiq, before_script].
The container image
Each CLI release is also an image, ghcr.io/conductionnl/keepiq-cli, with the same version:
docker run --rm -e KEEPIQ_URL -e KEEPIQ_APP_ID -e KEEPIQ_APP_KEY ghcr.io/conductionnl/keepiq-cli:0.3.0 ci fetch DB_PASSWORD --output json
Next step
Register the application your pipeline will use, then add its key to your CI secrets. See OpenConnector integration for how registration and approval work.