ci: weekly production smoke for workspace service tokens - #1040
Conversation
|
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (2)
🚫 Excluded labels (none allowed) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
In plain terms
Adds a small production check for workspace service tokens. It uses the
UPLOADS_SERVICE_TOKENrepo secret the way a CI job would: the CLI built from this checkout, with only the token set. It uploads a tiny image and checks the upload is attributed to the service token.What it does / what it is not
UPLOADS_WORKSPACEset. Agh.*-tagged upload getsgh.uploader-kind: serviceand a label ingh.uploader, with nogh.uploader-id.screenshots/smoke/service-token.webp,--replace). Only one smoke file ever exists.up_(a token minted before feat: give workspace service tokens a ups_ prefix #1039). Never prints the token.Test plan
defaultand attributed the upload to the token's label as a service.