Skip to content

fix: use a GitHub App token in the GeoLite update workflow - #508

Merged
abhalsod-sonata merged 1 commit into
release-ulmofrom
abhalsod/LP-1331-geolite-github-app-token
Oct 8, 2026
Merged

abhalsod-sonata merged 1 commit into
release-ulmofrom
abhalsod/LP-1331-geolite-github-app-token

Conversation

@abhalsod-sonata

@abhalsod-sonata abhalsod-sonata commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Description

The "Update GeoLite Database" workflow has failed since 2026-10-01 (run 36809399679). gh pr create uses the GH_PAT_WITH_ORG secret, a personal access token whose owner account has been deactivated:

pull request create failed: GraphQL: must be a collaborator (createPullRequest)

SRE is moving away from personal access tokens and is creating a GitHub App for this workflow instead (DOS-7368). This PR switches the workflow to that App:

  • A new "Generate GitHub App token" step uses actions/create-github-app-token@v3 to exchange the App credentials for a short-lived installation token scoped to this repository.
  • gh pr create now uses that token instead of GH_PAT_WITH_ORG.
  • The branch push is unchanged and still uses the job's GITHUB_TOKEN.

Impacted roles: Developer / Operator (CI only, no runtime change).

GitHub App (requested in DOS-7368)

  • Proposed name: edx-platform-geolite-updater (final name is up to SRE)
  • Installed on edx/edx-platform only, no webhook
  • Repository permissions: Contents: Read and write, Pull requests: Read and write, Metadata: Read
  • Organization permissions: Members: Read, needed to request the edx/orbi-bom team as reviewer

SRE adds the App credentials directly as repository secrets in this repo. They are not shared outside GitHub (no Keeper, email or direct message).

  • GH_APP_CLIENT_ID: the App's Client ID (create-github-app-token@v3 uses client-id; app-id is deprecated)
  • GH_APP_PRIVATE_KEY: the App's private key

Merge plan

  1. Merge only after SRE confirms on DOS-7368 that both secrets are added. Until then the new step fails, the same way the workflow fails today.
  2. After merge, run the workflow manually (see Testing instructions).
  3. Once the run succeeds, report back on DOS-7368 so SRE can delete the old GH_PAT_WITH_ORG secret.

Supporting information

Testing instructions

  1. Confirm GH_APP_CLIENT_ID and GH_APP_PRIVATE_KEY exist under Settings > Secrets and variables > Actions.
  2. After merge, run the workflow manually:
    gh workflow run update-geolite-database.yml -R edx/edx-platform --ref release-ulmo
  3. Check that the "Generate GitHub App token" step passes and that the run opens a PR authored by the App (<app-name>[bot]) with edx/orbi-bom requested as reviewer.

Deadline

Before the next scheduled run on 2026-11-01.

@abhalsod-sonata
abhalsod-sonata requested a review from a team October 7, 2026 10:11
The GH_PAT_WITH_ORG secret is a personal access token whose owner
account was deactivated, so gh pr create fails with "must be a
collaborator". SRE is replacing personal access tokens with GitHub
Apps (DOS-7368).

Generate a short-lived installation token with
actions/create-github-app-token and use it for gh pr create. The App
credentials come from the GH_APP_CLIENT_ID and GH_APP_PRIVATE_KEY
repository secrets.

LP-1331
@abhalsod-sonata

Copy link
Copy Markdown
Member Author

Converting to draft until SRE creates the GitHub App and adds the GH_APP_CLIENT_ID and GH_APP_PRIVATE_KEY repository secrets (DOS-7368). Until then the new token step would fail.

Merge order

  1. fix: make GeoLite update workflow rerun-safe and fix shell quoting #501: rerun and quoting fixes. Already approved.
  2. fix: use a GitHub App token in the GeoLite update workflow #508 (this PR): merge after fix: make GeoLite update workflow rerun-safe and fix shell quoting #501. If GitHub reports this branch is out of date, update it from release-ulmo first. There are no conflicts.

After both are merged, run the workflow manually and confirm it opens a PR authored by the App:
gh workflow run update-geolite-database.yml -R edx/edx-platform --ref release-ulmo

@abhalsod-sonata
abhalsod-sonata marked this pull request as ready for review October 8, 2026 10:34
@abhalsod-sonata
abhalsod-sonata merged commit 209ee12 into release-ulmo Oct 8, 2026
65 checks passed
@abhalsod-sonata
abhalsod-sonata deleted the abhalsod/LP-1331-geolite-github-app-token branch October 8, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants