From 7eea5ce972f6b0ac807a337f5a452debce57ae25 Mon Sep 17 00:00:00 2001 From: -z <11802769+Aloento@users.noreply.github.com> Date: Thu, 24 Sep 2026 23:22:48 +0200 Subject: [PATCH 1/3] Push all images to the stackmon project and log in with organization secrets --- .github/workflows/docker-build.yaml | 44 ++++++++++------------------- 1 file changed, 15 insertions(+), 29 deletions(-) diff --git a/.github/workflows/docker-build.yaml b/.github/workflows/docker-build.yaml index d1e445b..bdb93ff 100644 --- a/.github/workflows/docker-build.yaml +++ b/.github/workflows/docker-build.yaml @@ -12,8 +12,6 @@ on: env: REGISTRY: swr.eu-de.otc.t-systems.com PROJECT: metrics-processor - # OTC project of the region, listed under "My Credentials > API Credentials" in the OTC console. - SWR_PROJECT: eu-de permissions: contents: read @@ -24,7 +22,7 @@ jobs: if: github.event_name == 'pull_request' runs-on: ubuntu-latest env: - ORG: stackmon-preprod + ORG: stackmon steps: - uses: actions/checkout@v7 @@ -50,12 +48,12 @@ jobs: labels: ${{ steps.meta.outputs.labels }} push: false - # Builds from main and manual runs land in the preprod project; only a release reaches stackmon. + # Builds from main and manual runs land in the stackmon project (the preprod cluster's pull secret only grants access to it); a release adds a semver tag. publish-preprod: if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest env: - ORG: stackmon-preprod + ORG: stackmon steps: - uses: actions/checkout@v7 @@ -74,24 +72,18 @@ jobs: - name: Login to Container Registry env: - SWR_AK: ${{ secrets.SWR_PREPROD_AK }} - SWR_SK: ${{ secrets.SWR_PREPROD_SK }} + SWR_URL: ${{ secrets.SWR_URL }} + SWR_USERNAME: ${{ secrets.SWR_USERNAME }} + SWR_PASSWORD: ${{ secrets.SWR_PASSWORD }} run: | set -euo pipefail - if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then - echo "The SWR_PREPROD_AK and SWR_PREPROD_SK repository secrets must be set" >&2 - exit 1 - fi - - # SWR authenticates with "@" and a login key derived from the AK/SK pair. - login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" - if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then - echo "Cannot derive the SWR login key from the AK/SK pair" >&2 + if [ -z "$SWR_URL" ] || [ -z "$SWR_USERNAME" ] || [ -z "$SWR_PASSWORD" ]; then + echo "The SWR_URL, SWR_USERNAME and SWR_PASSWORD organization secrets must be set" >&2 exit 1 fi - printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin + printf '%s' "$SWR_PASSWORD" | docker login "$SWR_URL" --username "$SWR_USERNAME" --password-stdin - name: Build and push uses: docker/build-push-action@v7 @@ -128,24 +120,18 @@ jobs: - name: Login to Container Registry env: - SWR_AK: ${{ secrets.SWR_AK }} - SWR_SK: ${{ secrets.SWR_SK }} + SWR_URL: ${{ secrets.SWR_URL }} + SWR_USERNAME: ${{ secrets.SWR_USERNAME }} + SWR_PASSWORD: ${{ secrets.SWR_PASSWORD }} run: | set -euo pipefail - if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then - echo "The SWR_AK and SWR_SK repository secrets must be set" >&2 - exit 1 - fi - - # SWR authenticates with "@" and a login key derived from the AK/SK pair. - login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" - if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then - echo "Cannot derive the SWR login key from the AK/SK pair" >&2 + if [ -z "$SWR_URL" ] || [ -z "$SWR_USERNAME" ] || [ -z "$SWR_PASSWORD" ]; then + echo "The SWR_URL, SWR_USERNAME and SWR_PASSWORD organization secrets must be set" >&2 exit 1 fi - printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin + printf '%s' "$SWR_PASSWORD" | docker login "$SWR_URL" --username "$SWR_USERNAME" --password-stdin - name: Build and push uses: docker/build-push-action@v7 From 2027cb0cb70516a1c7362d67b62b89a67b8c7a6e Mon Sep 17 00:00:00 2001 From: -z <11802769+Aloento@users.noreply.github.com> Date: Thu, 24 Sep 2026 23:45:38 +0200 Subject: [PATCH 2/3] Log in to SWR with the repository AK/SK pair again The organization secrets resolve and are in the documented shape, yet every login combination is denied; a probe confirmed this repository's SWR_AK/SK pair authenticates on the same registry. Keep pushing to stackmon/metrics-processor with sha tags. --- .github/workflows/docker-build.yaml | 44 +++++++++++++++++++++-------- 1 file changed, 32 insertions(+), 12 deletions(-) diff --git a/.github/workflows/docker-build.yaml b/.github/workflows/docker-build.yaml index bdb93ff..4471b4f 100644 --- a/.github/workflows/docker-build.yaml +++ b/.github/workflows/docker-build.yaml @@ -12,6 +12,8 @@ on: env: REGISTRY: swr.eu-de.otc.t-systems.com PROJECT: metrics-processor + # OTC project of the region, listed under "My Credentials > API Credentials" in the OTC console. + SWR_PROJECT: eu-de permissions: contents: read @@ -72,18 +74,29 @@ jobs: - name: Login to Container Registry env: - SWR_URL: ${{ secrets.SWR_URL }} - SWR_USERNAME: ${{ secrets.SWR_USERNAME }} - SWR_PASSWORD: ${{ secrets.SWR_PASSWORD }} + SWR_AK: ${{ secrets.SWR_AK }} + SWR_SK: ${{ secrets.SWR_SK }} run: | set -euo pipefail - if [ -z "$SWR_URL" ] || [ -z "$SWR_USERNAME" ] || [ -z "$SWR_PASSWORD" ]; then - echo "The SWR_URL, SWR_USERNAME and SWR_PASSWORD organization secrets must be set" >&2 + if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then + echo "The SWR_AK and SWR_SK repository secrets must be set" >&2 exit 1 fi - printf '%s' "$SWR_PASSWORD" | docker login "$SWR_URL" --username "$SWR_USERNAME" --password-stdin + # SWR rejects a raw SK, so the password has to be the login key derived + # from the AK/SK pair, with the username in "@" form. The + # organization secrets SWR_URL/SWR_USERNAME/SWR_PASSWORD hold a + # correctly shaped but dead credential: on 2026-09-24 every login + # combination, including the endpoint for the region named in the + # username, was denied, while this repository pair authenticates. + login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" + if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then + echo "Cannot derive the SWR login key from the AK/SK pair" >&2 + exit 1 + fi + + printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin - name: Build and push uses: docker/build-push-action@v7 @@ -120,18 +133,25 @@ jobs: - name: Login to Container Registry env: - SWR_URL: ${{ secrets.SWR_URL }} - SWR_USERNAME: ${{ secrets.SWR_USERNAME }} - SWR_PASSWORD: ${{ secrets.SWR_PASSWORD }} + SWR_AK: ${{ secrets.SWR_AK }} + SWR_SK: ${{ secrets.SWR_SK }} run: | set -euo pipefail - if [ -z "$SWR_URL" ] || [ -z "$SWR_USERNAME" ] || [ -z "$SWR_PASSWORD" ]; then - echo "The SWR_URL, SWR_USERNAME and SWR_PASSWORD organization secrets must be set" >&2 + if [ -z "$SWR_AK" ] || [ -z "$SWR_SK" ]; then + echo "The SWR_AK and SWR_SK repository secrets must be set" >&2 + exit 1 + fi + + # See the preprod channel above for why the organization secrets are + # not used. + login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" + if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then + echo "Cannot derive the SWR login key from the AK/SK pair" >&2 exit 1 fi - printf '%s' "$SWR_PASSWORD" | docker login "$SWR_URL" --username "$SWR_USERNAME" --password-stdin + printf '%s' "$login_key" | docker login "$REGISTRY" --username "${SWR_PROJECT}@${SWR_AK}" --password-stdin - name: Build and push uses: docker/build-push-action@v7 From bc43f34961421b490c0dab4bb60104d063d9b9f2 Mon Sep 17 00:00:00 2001 From: Aloento <11802769+Aloento@users.noreply.github.com> Date: Thu, 24 Sep 2026 23:47:21 +0200 Subject: [PATCH 3/3] Update docker-build.yaml --- .github/workflows/docker-build.yaml | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/.github/workflows/docker-build.yaml b/.github/workflows/docker-build.yaml index 4471b4f..bfd602d 100644 --- a/.github/workflows/docker-build.yaml +++ b/.github/workflows/docker-build.yaml @@ -12,7 +12,6 @@ on: env: REGISTRY: swr.eu-de.otc.t-systems.com PROJECT: metrics-processor - # OTC project of the region, listed under "My Credentials > API Credentials" in the OTC console. SWR_PROJECT: eu-de permissions: @@ -83,13 +82,7 @@ jobs: echo "The SWR_AK and SWR_SK repository secrets must be set" >&2 exit 1 fi - - # SWR rejects a raw SK, so the password has to be the login key derived - # from the AK/SK pair, with the username in "@" form. The - # organization secrets SWR_URL/SWR_USERNAME/SWR_PASSWORD hold a - # correctly shaped but dead credential: on 2026-09-24 every login - # combination, including the endpoint for the region named in the - # username, was denied, while this repository pair authenticates. + login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then echo "Cannot derive the SWR login key from the AK/SK pair" >&2 @@ -143,8 +136,6 @@ jobs: exit 1 fi - # See the preprod channel above for why the organization secrets are - # not used. login_key="$(printf '%s' "$SWR_AK" | openssl dgst -sha256 -hmac "$SWR_SK" | awk '{print $NF}')" if [[ ! "$login_key" =~ ^[0-9a-f]{64}$ ]]; then echo "Cannot derive the SWR login key from the AK/SK pair" >&2