Sign inSign up

docker/sbx-kit-gitlab:latest

Multi-platform
Manifest digest

sha256:7409805398f03614b20efa3a210c2b88dd8d93b4656c9593b252c8f6f5fba1f0

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:7409805398f03614b20efa3a210c2b88dd8d93b4656c9593b252c8f6f5fba1f0

yaml
schemaVersion: "3"
displayName: GitLab CLI (glab)
description: Installs the GitLab CLI (glab) with proxy-injected personal access token auth, so agents can work with GitLab projects the way gh works with GitHub. Targets gitlab.com by default and any self-managed instance via the host argument.
version: 1.118.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - ${{ kit.args.host }}
    - type: com.docker.sandbox/credential@1
      config:
        apiKey:
            inject:
                - domain: ${{ kit.args.host }}
                  format: Bearer %s
                  header: Authorization
            name: GITLAB_TOKEN
            proxyManaged: true
        phase: runtime
        service: ${{ kit.args.service }}
      description: GitLab personal access token (api scope) for the target instance. Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to that instance.
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: |
                set -euo pipefail
                CFG=/home/agent/.config/glab-cli/config.yml
                # install re-runs on recreate: never clobber a config the user has
                # since edited (or that `glab auth login` has written into).
                if [ ! -f "$CFG" ]; then
                  install -d -m 0700 -o agent -g agent /home/agent/.config/glab-cli
                  cat > "$CFG" <<'EOF'
                hosts:
                  ${{ kit.args.host }}:
                    api_host: ${{ kit.args.host }}
                    api_protocol: https
                    git_protocol: ssh
                EOF
                  chmod 600 "$CFG"
                  chown agent:agent "$CFG"
                fi
              description: Seed glab's host config so `glab auth status` recognizes the instance
              user: "0"
    - type: com.docker.sandbox/agent-context@1
      config:
        content: |
            ## GitLab CLI

            `glab` is installed and authenticated against ${{ kit.args.host }}
            through the sandbox proxy — `GITLAB_TOKEN` is a proxy-managed
            placeholder, never the real token. Use `glab api ...` for arbitrary
            GitLab REST calls and the usual `glab mr` / `glab issue` / `glab repo`
            subcommands. Verify auth with `glab auth status`.

            Only ${{ kit.args.host }} is authenticated. `GITLAB_TOKEN` holds a
            sentinel the proxy rewrites for that host alone, so a request to any
            other GitLab instance sends the literal sentinel and gets a 401 rather
            than falling back to anonymous access. Nothing secret is exposed by
            this; use a separate sandbox for a different instance.

            Git-over-HTTPS push/pull auth is NOT wired up by this kit (the sandbox
            proxy cannot rewrite git's Basic auth without breaking the Bearer auth
            `glab`/the API rely on — same domain, two schemes). For `git clone` /
            `git push` / `git pull`, use SSH remotes
            (`git@${{ kit.args.host }}:group/project.git`) — add the `gitlab-ssh`
            kit for passwordless host-key verification, and load your key with
            `ssh-add` on the host so it forwards into the sandbox.
args:
    host:
        default: gitlab.com
        description: GitLab instance hostname, e.g. gitlab.example.com for a self-managed instance
        pattern: ^[A-Za-z0-9][A-Za-z0-9.-]*$
        env: GITLAB_HOST
    service:
        default: gitlab
        description: Credential service name to bind with `sbx secret set`. Give a self-managed sandbox its own name (e.g. gitlab-acme) so it can hold a different PAT from a gitlab.com sandbox.
        pattern: ^[a-z0-9]([a-z0-9-]{0,62}[a-z0-9])?$
    version:
        default: 1.118.0
        description: glab release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: GLAB_VERSION