fix: add SSH-to-HTTPS git insteadOf config for terraform module pulls (CSVDIES-10219) #5
+26
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Add SSH-to-HTTPS git
insteadOfrewrite config to fixterraform initfailing with "Host key verification failed" on GitHub Actions runners.Purpose
GitHub Actions runners have no SSH keys for
github.e.it.census.gov. Terraform normalizes SCP-style SSH module source URLs tossh://git@...before invoking git, causingterraform initto fail.The fix adds two
git config --global url.insteadOfrules that transparently rewrite bothgit@github.e.it.census.gov:andssh://git@github.e.it.census.gov/to authenticated HTTPS using a short-lived GitHub App token viaCSVD/gh-auth@main.New optional inputs (backward compatible — steps skipped when
github_app_pem_fileis not provided):github_app_pem_filegithub_app_installation_idgithub_app_id(default: "6")Jira
CSVDIES-10219
tf-plan output
N/A — composite action, not a Terraform configuration.