Skip to content

Latest commit

 

History

History
70 lines (45 loc) · 5.53 KB

File metadata and controls

70 lines (45 loc) · 5.53 KB

Secrets management

This document covers SDK build/test and automation secrets. Normal SDK package publishing runs from github/copilot-agent-runtime through its publish.yml entry workflow, using runtime-repository credentials and trusted publishers. Curated release notes and Java SNAPSHOT publishing run in the public SDK repository using its credentials.

Warning

If any of these secrets expire or are revoked, the corresponding workflows will fail silently or with opaque permission errors. Review this list periodically and rotate secrets before they expire.

SDK test secrets

These secrets are used by the authoritative SDK build/test workflow.

  • COPILOT_DEVELOPER_CLI_INTEGRATION_HMAC_KEY: HMAC key used to authenticate with the Copilot Developer CLI integration endpoint during tests. Injected as COPILOT_HMAC_KEY in test environments.
    • Workflows: sdk.yml

Agentic workflow secrets

These secrets power the GitHub Agentic Workflows (gh-aw) used for issue triage, code generation, and release automation.

  • COPILOT_GITHUB_TOKEN: GitHub OAuth token consumed by the Copilot CLI for AI authentication. Required by all agentic workflows when invoking copilot for AI inference.

    • Workflows: issue-triage.lock.yml, issue-classification.lock.yml, handle-bug.lock.yml, handle-enhancement.lock.yml, handle-question.lock.yml, handle-documentation.lock.yml, java-codegen-check.yml, java-codegen-fix.lock.yml, java-smoke-test.yml, java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml, release-changelog.lock.yml, cross-repo-issue-analysis.lock.yml
  • GH_AW_GITHUB_TOKEN: Optional GitHub token override for repository operations (reading code, creating pull requests, and making GitHub API calls). If unset, workflows use the automatic GITHUB_TOKEN.

    • Workflows: issue-triage.lock.yml, issue-classification.lock.yml, handle-bug.lock.yml, handle-enhancement.lock.yml, handle-question.lock.yml, handle-documentation.lock.yml, java-codegen-fix.lock.yml, java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml, release-changelog.lock.yml, cross-repo-issue-analysis.lock.yml
  • GH_AW_GITHUB_MCP_SERVER_TOKEN: Optional token override for the GitHub MCP server container. If unset, workflows fall back to GH_AW_GITHUB_TOKEN and then the automatic GITHUB_TOKEN.

    • Workflows: issue-triage.lock.yml, issue-classification.lock.yml, handle-bug.lock.yml, handle-enhancement.lock.yml, handle-question.lock.yml, handle-documentation.lock.yml, java-codegen-fix.lock.yml, java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml, release-changelog.lock.yml, cross-repo-issue-analysis.lock.yml
  • GH_AW_CI_TRIGGER_TOKEN: Token used to trigger CI workflows from within agentic workflow runs.

    • Workflows: java-codegen-fix.lock.yml, java-adapt-handwritten-code-to-accept-upgrade-changes.lock.yml, release-changelog.lock.yml
  • RUNTIME_TRIAGE_TOKEN: GitHub token with issue write access to both github/copilot-sdk and github/copilot-agent-runtime, and read access to github/copilot-agent-runtime contents. Used to clone that repository, add labels to the source issue, create linked runtime issues, and make GitHub API calls.

    • Workflows: cross-repo-issue-analysis.lock.yml

Java publishing secrets

These secrets support Java SDK Maven Central publishing and post-release documentation deployment from the runtime repository. The SDK-side Java SNAPSHOT workflow uses JAVA_MAVEN_CENTRAL_USERNAME and JAVA_MAVEN_CENTRAL_PASSWORD in this repository.

  • JAVA_MAVEN_CENTRAL_USERNAME: Username generated by a Maven Central Portal user token.

    • Runtime repository (github/copilot-agent-runtime): publish.yml and sdk-publish-release.yml
    • SDK repository (github/copilot-sdk): java-publish-snapshot.yml
  • JAVA_MAVEN_CENTRAL_PASSWORD: Password or token for Maven Central (Sonatype OSSRH) authentication.

    • Runtime repository (github/copilot-agent-runtime): publish.yml and sdk-publish-release.yml
    • SDK repository (github/copilot-sdk): java-publish-snapshot.yml
  • JAVA_GPG_SECRET_KEY: GPG private key used to sign Java release artifacts for Maven Central.

    • Runtime workflow: publish.yml and its reusable SDK publishing jobs
  • JAVA_GPG_PASSPHRASE: Passphrase for the GPG signing key.

    • Runtime workflow: publish.yml and its reusable SDK publishing jobs
  • JAVA_RELEASE_GITHUB_TOKEN: GitHub token with workflow dispatch (actions:write) permission on github/copilot-sdk-java. Used to trigger the documentation site deployment after a release is published.

    • Workflows: publish.yml

Rust publishing secret

  • CARGO_REGISTRY_TOKEN: Authentication token for publishing the Rust SDK crate to crates.io.
    • Workflows: publish.yml

Secrets not managed in this repository

  • GITHUB_TOKEN: Automatically provided by GitHub Actions. No manual management required. SDK release packaging consumes runtime artifacts from the same workflow run instead of acquiring private runtime packages from GitHub Packages.

Further reading