Skip to content

[release/8.0] Add scripts for obtaining GitHub app tokens in pipelines - #17298

Merged
premun merged 1 commit into
dotnet:release/8.0from
premun:prvysoky/github-app-tokens
Aug 10, 2026
Merged

premun merged 1 commit into
dotnet:release/8.0from
premun:prvysoky/github-app-tokens

Conversation

@premun

@premun premun commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

Backport of #17261

Will be needed for dotnet/arcade-services#6531 in installer's 8.0 branch

@premun
premun requested review from missymessa and a lite review from Copilot August 10, 2026 14:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds shared Azure Pipelines templates and a PowerShell helper to mint short-lived GitHub App installation tokens (via Key Vault signing + GitHub API exchange) so pipelines can authenticate without long-lived PATs, aligning with the backport needs for release/8.0.

Changes:

  • Introduces a core Azure Pipelines step template to acquire a GitHub App installation token.
  • Adds “official” vs “non-official” wrapper step templates intended to route to the same core implementation.
  • Adds Get-GitHubAppToken.ps1 to sign a JWT with an Azure Key Vault key and exchange it for an installation access token.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

File Description
eng/common/core-templates/steps/get-github-app-token.yml Core AzureCLI step that calls the PowerShell token-minting script.
eng/common/templates/steps/get-github-app-token.yml Non-official wrapper for the core template (parameter forwarding).
eng/common/templates-official/steps/get-github-app-token.yml Official wrapper for the core template (parameter forwarding).
eng/common/Get-GitHubAppToken.ps1 Implements JWT signing via Key Vault and installation token minting via GitHub API.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1 to +7
steps:
- template: /eng/common/core-templates/steps/get-github-app-token.yml
parameters:
is1ESPipeline: false

${{ each parameter in parameters }}:
${{ parameter.key }}: ${{ parameter.value }}
Comment on lines +48 to +50
- name: is1ESPipeline
type: boolean

Comment on lines +139 to +145
if ($OutputVariableName) {
Write-Host "Setting pipeline variable '$OutputVariableName'."
Write-Host "##vso[task.setvariable variable=$OutputVariableName;issecret=true]$($tokenResponse.token)"
}
else {
Write-Host $tokenResponse.token -ForegroundColor Green
}
Comment on lines +1 to +7
steps:
- template: /eng/common/core-templates/steps/get-github-app-token.yml
parameters:
is1ESPipeline: true

${{ each parameter in parameters }}:
${{ parameter.key }}: ${{ parameter.value }}
@premun
premun enabled auto-merge (squash) August 10, 2026 14:56
@premun
premun merged commit 1394072 into dotnet:release/8.0 Aug 10, 2026
10 of 13 checks passed
@premun
premun deleted the prvysoky/github-app-tokens branch September 2, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants