Skip to content

Read the CI test key from Secret Manager and keep it out of test ids - #400

Merged
lcbill merged 1 commit into
masterfrom
bt-cicd-key-secret-manager
Sep 25, 2026
Merged

lcbill merged 1 commit into
masterfrom
bt-cicd-key-secret-manager

Conversation

@lcbill

@lcbill lcbill commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Why

The Cloud Build integration-test API key was a plaintext _KEY trigger substitution, visible to anyone who can view triggers or build records in the project. On top of that, tests/integration/conftest.py parametrized key directly from --key, so pytest embedded the key value in every test id and the verbose build log printed it once per integration test (127 occurrences in the latest PR build). Same class of issue as refractionPOINT/go-limacharlie#273.

Context: https://refractionpoint.slack.com/archives/C8JU6GVEG/p1790334000912869

Changes

  • cloudbuild_pr.yaml: the key is read from Secret Manager (PYTHON_LIMACHARLIE_TEST_KEY) via availableSecrets + secretEnv on the Integration Tests step and passed to pytest as --key="$$_KEY" from the environment. _OID stays a substitution (not secret). substitutionOption: ALLOW_LOOSE tolerates the legacy _KEY trigger substitution until it is removed from the trigger.
  • tests/integration/conftest.py: oid and key parametrizations get constant ids ([oid-key]), so neither value appears in test ids or logs.

Rollout

  1. Secret PYTHON_LIMACHARLIE_TEST_KEY already exists in the build project with a freshly minted key (identical permission set to the current one); the Cloud Build service account already has secretAccessor.
  2. This PR's own Cloud Build run exercises the Secret Manager path end to end; its log will be checked for zero occurrences of the key.
  3. After merge: remove _KEY from the python-limacharlie and (disabled) python-limacharlie-release triggers, revoke the old cloudbuild key.

Test plan

  • pytest --collect-only tests/integration --oid=… --key=SENTINEL: 165 tests collected, ids are [oid-key], sentinel appears 0 times
  • cloudbuild_pr.yaml parses; no ${_KEY} references remain
  • Cloud Build PR run green, integration step authenticates with the Secret Manager key, log contains no key value

The integration-test org key was passed to Cloud Build as a plaintext
trigger substitution, readable by anyone who can view triggers or build
records in the project. Worse, conftest parametrized the key straight from
the CLI option, so pytest embedded its value in every test id and the
verbose build log printed it once per test.

The build now reads the key from the PYTHON_LIMACHARLIE_TEST_KEY secret via
availableSecrets/secretEnv and passes it to pytest from the environment, and
the oid/key parametrizations use constant ids so neither value appears in
test ids or logs.

substitutionOption ALLOW_LOOSE lets the build tolerate the legacy _KEY
trigger substitution until it is removed from the trigger.
@lcbill
lcbill requested a review from maximelb September 25, 2026 15:27
@lcbill
lcbill enabled auto-merge (squash) September 25, 2026 15:27
@lcbill
lcbill merged commit 749f7ed into master Sep 25, 2026
6 checks passed
@lcbill
lcbill deleted the bt-cicd-key-secret-manager branch September 25, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants