Sign inSign up

djordjelukic1639080/cbx-example-github-repo:1

Manifest digest

sha256:b94ce09d27551afaee0bfd00eb9f488feacf39a7bd170d805b32b792a1939a7f

Last pushed

about 10 hours by djordjelukic1639080

Type

Sandbox Kit

Manifest digest

sha256:b94ce09d27551afaee0bfd00eb9f488feacf39a7bd170d805b32b792a1939a7f

yaml
schemaVersion: "3"
displayName: GitHub repository
description: Clones a GitHub repository into the workspace when the sandbox is created, and lets git fetch from and push to that repository only.
version: 1.0.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@2
      config:
        install:
            allow:
                - hosts:
                    - github.com
                  methods:
                    - GET
                    - POST
                  paths:
                    - /${{ kit.args.repo }}.git/**
                    - /${{ kit.args.repo }}/**
        runtime:
            allow:
                - hosts:
                    - github.com
                  methods:
                    - GET
                    - POST
                  paths:
                    - /${{ kit.args.repo }}.git/**
                    - /${{ kit.args.repo }}/**
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: github.com
                  scheme: basic
                  username: x-access-token
            name: GH_TOKEN
            proxyManaged: true
        phase:
            - install
            - runtime
        service: github
      description: GitHub token to clone and push to the repository
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: |
                set -eu
                if [ -d "$GITHUB_REPO_DIR/.git" ]; then
                  echo "github-repo: $GITHUB_REPO_DIR already holds a clone; leaving it"
                  exit 0
                fi
                mkdir -p "$GITHUB_REPO_DIR"
                if [ -n "$(ls -A "$GITHUB_REPO_DIR")" ]; then
                  echo "github-repo: $GITHUB_REPO_DIR is not empty; refusing to clone into it" >&2
                  exit 1
                fi
                git clone --quiet "https://github.com/$GITHUB_REPO.git" "$GITHUB_REPO_DIR"
                echo "github-repo: cloned $GITHUB_REPO into $GITHUB_REPO_DIR"
              description: Clone the repository into the workspace
              env:
                - GITHUB_REPO
                - GITHUB_REPO_DIR
                - HTTP_PROXY
                - HTTPS_PROXY
                - http_proxy
                - https_proxy
              user: agent
    - type: com.docker.sandbox/agent-context@1
      config:
        content: |
            The GitHub repository ${{ kit.args.repo }} is cloned at
            ${{ kit.args.dir }}. git can fetch from and push to that repository
            over HTTPS; other repositories and the GitHub API are not reachable.
args:
    dir:
        default: /home/agent/workspace
        description: Absolute directory to clone into
        pattern: /[A-Za-z0-9_.-]+(?:/[A-Za-z0-9_.-]+)*
        env: GITHUB_REPO_DIR
    repo:
        required: true
        description: GitHub repository to clone, as owner/name
        pattern: '[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})/(?:[A-Za-z0-9_.-]*(?:[A-Za-su-z0-9_-]|[A-Za-hj-z0-9_.-]t|[A-Za-fh-z0-9_.-]it|[A-Za-z0-9_-]git)|t|it|git)'
        env: GITHUB_REPO