An Action to set up duplocloud cli and the underlying cloud. During this process, duplo discovers the underlying cloud which is either aws, gcp, or azure. Once the cloud is known, the corresponding cli is installed. Finally the action will authenticate with the cloud provider. It provides the following features:
- Setting up Python.
- Installing
duploctl. - when AWS
- Installing AWS CLI.
- Running Duplo JIT (Just-In-Time) for AWS.
- Configuring AWS IAM Credentials.
- when GCP
- Installing GCP CLI.
- Running Duplo JIT (Just-In-Time) for GCP.
- Configuring GCP SA Credentials.
- when Azure
- Installing Azure CLI.
- Configuring Azure SCP Credentials.
The following input variables can be configured:
| Name | Description | Required | Default Value |
|---|---|---|---|
mask-account-id |
Mask AWS Account ID in logs | false |
false |
region |
Overide the cloud region from the default. For gcp this is required. | false |
|
account-id |
Overide the cloud account id from the default. Required when on gcp/azure where this would be the project name or directory name. | false |
|
credentials |
Cloud credentials for Azure or GCP. Leave this null for gcp jit | false |
|
version |
Duplo version to install. | false |
latest |
jit |
Enable JIT (Just-In-Time) authentication for cloud providers. | false |
true |
cloud-cli |
Enable cloud CLI installation and configuration (AWS CLI, gcloud, Azure CLI). | false |
true |
mode |
Deployment mode: portal, helpdesk (standalone AI HelpDesk), or auto (detect from the token — dahp_ tokens are helpdesk API tokens). In helpdesk mode the portal discovery, cloud JIT, and cloud CLI steps are skipped. |
false |
auto |
JIT for AWS/GCP Example:
name: Quick Setup
on:
- push
jobs:
build:
runs-on: ubuntu-latest
env:
DUPLO_TOKEN: ${{ secrets.DUPLO_TOKEN }}
DUPLO_HOST: ${{ vars.DUPLO_HOST }}
DUPLO_TENANT: ${{ vars.DUPLO_TENANT }}
steps:
- name: Duplo Setup
uses: duplocloud/actions@<VERSION OF THIS ACTION>
with:
version: <DUPLOCTL VERSION>Standalone AI HelpDesk Example:
For a standalone AI HelpDesk, set DUPLO_HOST to the helpdesk URL and DUPLO_TOKEN to a dahp_ API token minted from the helpdesk. The action detects the token prefix and skips the portal discovery and cloud JIT/CLI steps; no DUPLO_TENANT is needed. Pass mode: helpdesk to make the choice explicit instead of relying on detection.
steps:
- name: Duplo Setup
uses: duplocloud/actions@<VERSION OF THIS ACTION>
env:
DUPLO_HOST: ${{ vars.DUPLO_HOST }} # https://my-helpdesk.example.com
DUPLO_TOKEN: ${{ secrets.DUPLO_TOKEN }} # dahp_...GCP or Azure Example with Credentials:
This uses given credentials to setup GCP or Azure. The name of the account is required for GCP and Azure as well. For GCP the account is the project id and for Azure it is the directory id.
steps:
- name: Duplo Setup
uses: duplocloud/actions@<VERSION OF THIS ACTION>
with:
account-id: ${{ vars.CLOUD_ACCOUNT }}
credentials: ${{ secrets.CLOUD_CREDENTIALS }}
version: <DUPLOCTL VERSION>Each underlying cloud has their own unique way of authenticating.
Using the JIT functionality built into the portal, the action uses retreives an sts session from the duplo portal and uses these credentials to authenticate with the AWS CLI. Magical.
The action uses the azure/login action to authenticate with Azure. To keep things consistent this action will use the CLOUD_CREDENTIALS secret to authenticate which expects the following format:
{
"clientId": "<client-id>",
"clientSecret": "<client-secret>",
"subscriptionId": "<subscription-id>",
"tenantId": "<tenant-id>"
}When no credentials are given, duploctl will run the JIT command for GCP and configure the GCP environment. The action uses the google-github-actions/setup-gcloud action to authenticate with GCP when credentials are given. To keep things consistent this action will use the CLOUD_CREDENTIALS secret to authenticate which expects the following format:
{
"type": "service_account",
"project_id": "<project-id>",
"private_key_id": "<private-key-id>",
"private_key": "<private-key>",
"client_email": "<client-email>",
"client_id": "<client-id>",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://accounts.google.com/o/oauth2/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "<client-x509-cert-url>"
}This repo is a mono repo for a number of useful actions. The main action is the setup action. Once all the tools are installed by running the setup action, the other actions can be used.
This action is used to update the image of a service in Duplo. It is a simple action that takes the service name and the image name as inputs.
A wrapper for the docker build or buildx command. This action is used to build a docker image and push it to a registry.
This action is used to install the necessary dependencies for working with Terraform. It supports caching of Terraform and TFLint plugins to improve performance.
Sets up a Terraform module for use in a GitHub Action.
Runs plan/apply/destroy on a Terraform module.
Import a list resources into a Terraform state file.
Import a list resources into a Terraform state file.
Runs a Kubernetes job in an AI HelpDesk workspace and waits for it to complete.
Fetches just-in-time Kubernetes credentials for an AI HelpDesk cluster and writes a kubeconfig for kubectl/helm steps.
Bulk-updates container images for multiple HelpDesk V2 workloads in an AI HelpDesk workspace.
Mints just-in-time AWS credentials from an AI HelpDesk workspace and exports them for later steps.
The scripts and documentation in this project are released under the MIT License.
- Third Party Actions:
- actions/cache@v5
- actions/create-github-app-token@v3
- actions/setup-python@v6
- actions/upload-artifact@v7
- aws-actions/amazon-ecr-login@v2
- aws-actions/configure-aws-credentials@v6
- azure/CLI@v3
- azure/login@v3
- crazy-max/ghaction-github-runtime@v4
- docker/login-action@v4
- docker/setup-buildx-action@v4
- docker/setup-qemu-action@v4
- google-github-actions/auth@v3
- google-github-actions/setup-gcloud@v3
- hashicorp/setup-terraform@v4
- terraform-linters/setup-tflint@v6
- unfor19/install-aws-cli-action@v1