426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
145 lines
4.5 KiB
TypeScript
145 lines
4.5 KiB
TypeScript
#!/usr/bin/env bun
|
||
/**
|
||
* Credential feed for the live multi-account CI lane (#9960).
|
||
*
|
||
* Reads the machine's connected coding-agent credentials — the Codex
|
||
* `~/.codex/auth.json` (refreshed via the same refresh logic the runtime uses)
|
||
* and the Claude Code OAuth token — and emits the minimal blobs that
|
||
* `live-multi-account-e2e.ts` seeds the pool from, so a scheduled lane can run
|
||
* real-account rotation. Pair this with a scheduled refresh (the Codex token is
|
||
* short-lived) to keep the CI secrets live.
|
||
*
|
||
* Usage:
|
||
* bun scripts/export-ci-account-secrets.ts [--index N] [--out FILE] [--gh]
|
||
*
|
||
* --index N suffix for the emitted var names (default 1) — run once per
|
||
* connected account, bumping N, to seed 2× each for rotation.
|
||
* --out FILE append `NAME=value` lines to FILE (a dotenv for the runner).
|
||
* --gh print `gh secret set` commands (review before running).
|
||
*
|
||
* Env overrides:
|
||
* CODEX_AUTH_PATH path to auth.json (default ~/.codex/auth.json)
|
||
* CLAUDE_CODE_OAUTH_TOKEN the Claude token to export (else skipped)
|
||
*
|
||
* Secrets are printed to stdout — run in a trusted shell, never in CI logs.
|
||
*/
|
||
|
||
import { appendFileSync, readFileSync } from "node:fs";
|
||
import os from "node:os";
|
||
import path from "node:path";
|
||
|
||
interface Args {
|
||
index: number;
|
||
out?: string;
|
||
gh: boolean;
|
||
}
|
||
|
||
function parseArgs(argv: string[]): Args {
|
||
const args: Args = { index: 1, gh: false };
|
||
for (let i = 0; i < argv.length; i++) {
|
||
const a = argv[i];
|
||
if (a === "--index")
|
||
args.index = Number.parseInt(argv[++i] ?? "1", 10) || 1;
|
||
else if (a === "--out") args.out = argv[++i];
|
||
else if (a === "--gh") args.gh = true;
|
||
}
|
||
return args;
|
||
}
|
||
|
||
function emit(name: string, value: string, args: Args): void {
|
||
// The value itself is never echoed to stdout in --gh mode beyond the command
|
||
// the operator runs locally; the dotenv path is for a trusted runner.
|
||
if (args.out) {
|
||
appendFileSync(args.out, `${name}=${value}\n`);
|
||
console.log(`[export] wrote ${name} -> ${args.out}`);
|
||
}
|
||
if (args.gh) {
|
||
console.log(
|
||
`gh secret set ${name} --body '${value.replace(/'/g, "'\\''")}'`,
|
||
);
|
||
}
|
||
if (!args.out && !args.gh) {
|
||
console.log(`${name}=${value}`);
|
||
}
|
||
}
|
||
|
||
async function exportCodex(args: Args): Promise<boolean> {
|
||
const authPath =
|
||
process.env.CODEX_AUTH_PATH ??
|
||
path.join(os.homedir(), ".codex", "auth.json");
|
||
let raw: string;
|
||
try {
|
||
raw = readFileSync(authPath, "utf-8");
|
||
} catch {
|
||
console.error(
|
||
`[export] no Codex auth.json at ${authPath} — skipping Codex`,
|
||
);
|
||
return false;
|
||
}
|
||
// Refresh in place if expired, using the runtime's own refresh logic, so the
|
||
// exported blob is fresh for the lane.
|
||
try {
|
||
const { loadCodexAuth, isExpired, refreshCodexAuth } = await import(
|
||
"../../plugin-codex-cli/src/codex-auth.ts"
|
||
);
|
||
const auth = await loadCodexAuth(authPath);
|
||
if (isExpired(auth)) {
|
||
console.error("[export] Codex token expired — refreshing");
|
||
await refreshCodexAuth(auth, authPath);
|
||
raw = readFileSync(authPath, "utf-8");
|
||
}
|
||
} catch (err) {
|
||
console.error(
|
||
`[export] Codex refresh skipped (${err instanceof Error ? err.message : String(err)}); exporting current blob`,
|
||
);
|
||
}
|
||
// Validate it's a usable ChatGPT login before emitting.
|
||
const parsed = JSON.parse(raw);
|
||
if (!parsed?.tokens?.access_token || !parsed?.tokens?.account_id) {
|
||
console.error("[export] Codex auth.json is not a ChatGPT login — skipping");
|
||
return false;
|
||
}
|
||
emit(
|
||
`ELIZA_LIVE_CODEX_AUTH_JSON_${args.index}`,
|
||
JSON.stringify(parsed),
|
||
args,
|
||
);
|
||
return true;
|
||
}
|
||
|
||
function exportClaude(args: Args): boolean {
|
||
const token = process.env.CLAUDE_CODE_OAUTH_TOKEN?.trim();
|
||
if (!token) {
|
||
console.error(
|
||
"[export] CLAUDE_CODE_OAUTH_TOKEN not set — skipping Claude (set it to export)",
|
||
);
|
||
return false;
|
||
}
|
||
emit(`ELIZA_LIVE_CLAUDE_OAUTH_TOKEN_${args.index}`, token, args);
|
||
return true;
|
||
}
|
||
|
||
async function main(): Promise<number> {
|
||
const args = parseArgs(process.argv.slice(2));
|
||
const codex = await exportCodex(args);
|
||
const claude = exportClaude(args);
|
||
if (!codex && !claude) {
|
||
console.error(
|
||
"[export] nothing exported — no connected Codex or Claude credential found",
|
||
);
|
||
return 1;
|
||
}
|
||
console.error(
|
||
`[export] done (index ${args.index}): codex=${codex} claude=${claude}`,
|
||
);
|
||
return 0;
|
||
}
|
||
|
||
main().then(
|
||
(code) => process.exit(code),
|
||
(err) => {
|
||
console.error("[export] error:", err);
|
||
process.exit(2);
|
||
},
|
||
);
|