sha256:7409805398f03614b20efa3a210c2b88dd8d93b4656c9593b252c8f6f5fba1f0
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:7409805398f03614b20efa3a210c2b88dd8d93b4656c9593b252c8f6f5fba1f0
schemaVersion: "3"
displayName: GitLab CLI (glab)
description: Installs the GitLab CLI (glab) with proxy-injected personal access token auth, so agents can work with GitLab projects the way gh works with GitHub. Targets gitlab.com by default and any self-managed instance via the host argument.
version: 1.118.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- ${{ kit.args.host }}
- type: com.docker.sandbox/credential@1
config:
apiKey:
inject:
- domain: ${{ kit.args.host }}
format: Bearer %s
header: Authorization
name: GITLAB_TOKEN
proxyManaged: true
phase: runtime
service: ${{ kit.args.service }}
description: GitLab personal access token (api scope) for the target instance. Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to that instance.
- type: com.docker.sandbox/lifecycle@1
config:
install:
- command: |
set -euo pipefail
CFG=/home/agent/.config/glab-cli/config.yml
# install re-runs on recreate: never clobber a config the user has
# since edited (or that `glab auth login` has written into).
if [ ! -f "$CFG" ]; then
install -d -m 0700 -o agent -g agent /home/agent/.config/glab-cli
cat > "$CFG" <<'EOF'
hosts:
${{ kit.args.host }}:
api_host: ${{ kit.args.host }}
api_protocol: https
git_protocol: ssh
EOF
chmod 600 "$CFG"
chown agent:agent "$CFG"
fi
description: Seed glab's host config so `glab auth status` recognizes the instance
user: "0"
- type: com.docker.sandbox/agent-context@1
config:
content: |
## GitLab CLI
`glab` is installed and authenticated against ${{ kit.args.host }}
through the sandbox proxy — `GITLAB_TOKEN` is a proxy-managed
placeholder, never the real token. Use `glab api ...` for arbitrary
GitLab REST calls and the usual `glab mr` / `glab issue` / `glab repo`
subcommands. Verify auth with `glab auth status`.
Only ${{ kit.args.host }} is authenticated. `GITLAB_TOKEN` holds a
sentinel the proxy rewrites for that host alone, so a request to any
other GitLab instance sends the literal sentinel and gets a 401 rather
than falling back to anonymous access. Nothing secret is exposed by
this; use a separate sandbox for a different instance.
Git-over-HTTPS push/pull auth is NOT wired up by this kit (the sandbox
proxy cannot rewrite git's Basic auth without breaking the Bearer auth
`glab`/the API rely on — same domain, two schemes). For `git clone` /
`git push` / `git pull`, use SSH remotes
(`git@${{ kit.args.host }}:group/project.git`) — add the `gitlab-ssh`
kit for passwordless host-key verification, and load your key with
`ssh-add` on the host so it forwards into the sandbox.
args:
host:
default: gitlab.com
description: GitLab instance hostname, e.g. gitlab.example.com for a self-managed instance
pattern: ^[A-Za-z0-9][A-Za-z0-9.-]*$
env: GITLAB_HOST
service:
default: gitlab
description: Credential service name to bind with `sbx secret set`. Give a self-managed sandbox its own name (e.g. gitlab-acme) so it can hold a different PAT from a gitlab.com sandbox.
pattern: ^[a-z0-9]([a-z0-9-]{0,62}[a-z0-9])?$
version:
default: 1.118.0
description: glab release to install
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: GLAB_VERSION