Passing secrets to act without putting them in a file #6185
|
I know about
What I really want is to pull them from my system keychain or from 1Password CLI. Has anyone set up something like this? I was thinking of a wrapper script that does: act push $(op item get "CI Secrets" --format json | jq -r '.fields[] | "-s \(.label)=\(.value)"')But I'm not sure if act handles that many |
Replies: 1 comment
|
the echo ".secrets" >> .gitignorethen: act push --secret-file .secretsfor the 1password approach, write to a tmpfile instead of inline expansion — avoids the quoting nightmare with special characters: op item get "CI Secrets" --format json \
| jq -r '.fields[] | "\(.label)=\(.value)"' > /tmp/.act-secrets
act push --secret-file /tmp/.act-secrets
rm /tmp/.act-secretsthe tmpfile path is cleaner than chaining |
the
.secretsfile approach is fine, just make sure it's gitignored before you create it:then:
for the 1password approach, write to a tmpfile instead of inline expansion — avoids the quoting nightmare with special characters:
the tmpfile path is cleaner than chaining
-sflags and keeps nothing in shell history.