JuliaRegistries / JuliaRegistries/CompatHelper.jl

Using org-level DOCUMENTER_KEY

Open
#410 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Julia
Stars
147
Forks
43
Avg merge
21h 27m
Merged PRs (30d)
2

Description

In my lab's organization, we have several packages that lack their own documenter documentation, and so don't have a public/private key/secret pair for documenter. However, we do have an organization-level DOCUMENTER_KEY. One example of such a package is https://github.com/HolyLab/ExtractPSF.jl. I have CompatHelper set up but it fails. Here's the relevant section of the [log](https://github.com/HolyLab/ExtractPSF.jl/runs/5819047730?check_suite_focus=true):

```
Run import CompatHelper
import CompatHelper
CompatHelper.main()
shell: /usr/bin/julia --color=yes {0}
env:
GITHUB_TOKEN: ***
COMPATHELPER_PRIV: ***
Cloning into '/tmp/jl_Zl4CYh/REPO'...
Already on 'master'
Your branch is up to date with 'origin/master'.
Cloning into '/tmp/jl_b88E8j/General'...
[ Info: EnvVar `COMPATHELPER_PRIV` is defined, nonempty, and not `false`
[ Info: This doesn't look like a raw SSH private key. I will assume that it is a Base64-encoded SSH private key. I will now try to Base64-decode it.
[ Info: This was a Base64-encoded SSH private key. I Base64-decoded it, and now I have the raw SSH private key.
Cloning into 'REPO'...
Warning: Permanently added the RSA host key for IP address '140.82.112.4' to the list of known hosts.
git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.
```
and so on.

I'm wondering if there's an easy way around this, short of setting up keys for each individual repository? (There are ~20 such repos, so it would be nice to solve this at the organization level.)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with CompatHelper.main and the GitHub Actions environment shown in the issue log, especially DOCUMENTER_KEY and COMPATHELPER_PRIV handling. Trace how repository cloning authenticates with GitHub and determine what organization-level secret support would need to cover. Done means an organization-level key can support the described repositories without individual repository keys, with tests or documented verification for the workflow.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, github-actions, julia
Domain
ci-cd, devops
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.