Skip to content

Commit a72ee9d

Browse files
Use Azure Trusted Signing when available (#1038)
1 parent 6ab8bd3 commit a72ee9d

File tree

2 files changed

+267
-11
lines changed

2 files changed

+267
-11
lines changed

.github/workflows/build-toolchain.yml

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -151,6 +151,14 @@ on:
151151
required: true
152152
R2_SECRET_ACCESS_KEY:
153153
required: true
154+
AZURE_SP_CREDENTIALS:
155+
required: false
156+
TRUSTED_SIGNING_ACCOUNT:
157+
required: false
158+
TRUSTED_SIGNING_TEST_PROFILE:
159+
required: false
160+
TRUSTED_SIGNING_PROD_PROFILE:
161+
required: false
154162

155163
jobs:
156164
context:
@@ -313,8 +321,7 @@ jobs:
313321
fi
314322
315323
if [[ "${{ github.event_name }}" == "schedule" || "${{ inputs.signed }}" == "true" ]]; then
316-
# FIXME(compnerd) enable this when requested
317-
echo signed=false >> ${GITHUB_OUTPUT}
324+
echo signed=true >> ${GITHUB_OUTPUT}
318325
else
319326
echo signed=false >> ${GITHUB_OUTPUT}
320327
fi
@@ -632,6 +639,10 @@ jobs:
632639
R2_ACCOUNT_ID: ${{ secrets.R2_ACCOUNT_ID }}
633640
R2_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }}
634641
R2_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }}
642+
AZURE_SP_CREDENTIALS: ${{ secrets.AZURE_SP_CREDENTIALS }}
643+
TRUSTED_SIGNING_ACCOUNT: ${{ secrets.TRUSTED_SIGNING_ACCOUNT }}
644+
TRUSTED_SIGNING_TEST_PROFILE: ${{ secrets.TRUSTED_SIGNING_TEST_PROFILE }}
645+
TRUSTED_SIGNING_PROD_PROFILE: ${{ secrets.TRUSTED_SIGNING_PROD_PROFILE }}
635646

636647
mac-build:
637648
# TODO: Enable the mac build.

0 commit comments

Comments
 (0)