Read the CI test key from Secret Manager and keep it out of test ids - #400
Merged
Merged
Conversation
The integration-test org key was passed to Cloud Build as a plaintext trigger substitution, readable by anyone who can view triggers or build records in the project. Worse, conftest parametrized the key straight from the CLI option, so pytest embedded its value in every test id and the verbose build log printed it once per test. The build now reads the key from the PYTHON_LIMACHARLIE_TEST_KEY secret via availableSecrets/secretEnv and passes it to pytest from the environment, and the oid/key parametrizations use constant ids so neither value appears in test ids or logs. substitutionOption ALLOW_LOOSE lets the build tolerate the legacy _KEY trigger substitution until it is removed from the trigger.
lcbill
enabled auto-merge (squash)
September 25, 2026 15:27
maximelb
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The Cloud Build integration-test API key was a plaintext
_KEYtrigger substitution, visible to anyone who can view triggers or build records in the project. On top of that,tests/integration/conftest.pyparametrizedkeydirectly from--key, so pytest embedded the key value in every test id and the verbose build log printed it once per integration test (127 occurrences in the latest PR build). Same class of issue as refractionPOINT/go-limacharlie#273.Context: https://refractionpoint.slack.com/archives/C8JU6GVEG/p1790334000912869
Changes
cloudbuild_pr.yaml: the key is read from Secret Manager (PYTHON_LIMACHARLIE_TEST_KEY) viaavailableSecrets+secretEnvon the Integration Tests step and passed to pytest as--key="$$_KEY"from the environment._OIDstays a substitution (not secret).substitutionOption: ALLOW_LOOSEtolerates the legacy_KEYtrigger substitution until it is removed from the trigger.tests/integration/conftest.py:oidandkeyparametrizations get constant ids ([oid-key]), so neither value appears in test ids or logs.Rollout
PYTHON_LIMACHARLIE_TEST_KEYalready exists in the build project with a freshly minted key (identical permission set to the current one); the Cloud Build service account already hassecretAccessor._KEYfrom thepython-limacharlieand (disabled)python-limacharlie-releasetriggers, revoke the oldcloudbuildkey.Test plan
pytest --collect-only tests/integration --oid=… --key=SENTINEL: 165 tests collected, ids are[oid-key], sentinel appears 0 timescloudbuild_pr.yamlparses; no${_KEY}references remain