Skip to content

WIP: Use Octo STS token exchange to run make-self-upgrade and renovate workflows - #373

Closed
erikgb wants to merge 28 commits into
mainfrom
octo-sts-poc
Closed

WIP: Use Octo STS token exchange to run make-self-upgrade and renovate workflows#373
erikgb wants to merge 28 commits into
mainfrom
octo-sts-poc

Conversation

@erikgb

@erikgb erikgb commented Aug 31, 2025

Copy link
Copy Markdown
Member

No description provided.

erikgb and others added 18 commits August 30, 2025 13:29
Signed-off-by: Erik Godding Boye
feat: enable Octo STS for downstream automation
Signed-off-by: Erik Godding Boye
…-sts-poc

[octo-sts-poc] Add ok-to-test label to downstream Renovate PRs
Use token obtained from Octo STS for Git operations
Signed-off-by: Erik Godding Boye
Add vendor-go target to Renovate postUpgradeTasks
Simplify use of Octo STS token in self-upgrade workflow
Signed-off-by: Erik Godding Boye
Signed-off-by: Erik Godding Boye
Signed-off-by: Erik Godding Boye
Signed-off-by: Erik Godding Boye
Align make-self-upgrade and renovate workflows
Grant make-self-upgrade write access to workflows
@cert-manager-prow cert-manager-prow Bot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. labels Aug 31, 2025
@cert-manager-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign thatsmrtalbot for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@cert-manager-prow cert-manager-prow Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Aug 31, 2025
erikgb and others added 6 commits August 31, 2025 12:56
Signed-off-by: Erik Godding Boye
Signed-off-by: octo-sts[bot] <157150467+octo-sts[bot]@users.noreply.github.com>
…github-actions

chore(deps): update misc github actions (octo-sts-poc)
Signed-off-by: Erik Godding Boye
Use Octo STS token to create self-upgrade PR
Add concurrency control to Renovate workflow
@cert-manager-prow cert-manager-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Aug 31, 2025
erikgb and others added 4 commits August 31, 2025 12:41
Signed-off-by: Erik Godding Boye
…-sts-poc

[octo-sts-poc] Add ok-to-test label to self-upgrade PRs
Signed-off-by: Erik Godding Boye
…-sts-poc

[octo-sts-poc] Set cert-manager-bot as Git author of Renovate PRs
@erikgb

erikgb commented Sep 1, 2025

Copy link
Copy Markdown
Member Author

Closing in favor of #385.

/close

@cert-manager-prow cert-manager-prow Bot closed this Sep 1, 2025
@cert-manager-prow

Copy link
Copy Markdown
Contributor

@erikgb: Closed this PR.

Details

In response to this:

Closing in favor of #385.

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant