From 2c40b0905960a567949f779b4dca372cc038576b Mon Sep 17 00:00:00 2001 From: Matt Miller Date: Tue, 28 Jul 2026 14:43:54 -0700 Subject: [PATCH] ci: dispatch to cloud with an App token instead of a PAT The PAT behind CLOUD_REPO_DISPATCH_TOKEN was regenerated without the Actions secret being updated, so the stored copy went stale. Every tag from v0.25.0 through v0.29.0 returned 401 and opened no cloud bump PR, which went unnoticed for six weeks because the bumps were filed by hand. Mint an installation token per run instead, scoped to Comfy-Org/cloud, so there is no stored credential left to drift or expire. --- .github/workflows/tag-dispatch-cloud.yml | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/.github/workflows/tag-dispatch-cloud.yml b/.github/workflows/tag-dispatch-cloud.yml index 53a0e91d6..84c529441 100644 --- a/.github/workflows/tag-dispatch-cloud.yml +++ b/.github/workflows/tag-dispatch-cloud.yml @@ -8,16 +8,36 @@ on: jobs: dispatch-cloud: runs-on: ubuntu-latest + # No checkout and no use of GITHUB_TOKEN; the dispatch goes out on the App + # token generated below, which is scoped to Comfy-Org/cloud only. + permissions: + contents: read steps: + # A PAT was used here previously. It was silently regenerated upstream + # without the Actions secret being updated, so every tag from v0.25.0 + # (2026-06-16) through v0.29.0 dispatched a 401 and no cloud bump PR was + # opened for six weeks. App installation tokens are minted per run and + # cannot drift out of sync with a stored copy. + - name: Generate GitHub App token + id: app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 + with: + app-id: ${{ secrets.FEN_RELEASE_APP_ID }} + private-key: ${{ secrets.FEN_RELEASE_PRIVATE_KEY }} + # Cross-repo dispatch: without these the token is scoped to this + # repository and the POST to cloud would 403. + owner: Comfy-Org + repositories: cloud + - name: Send repository dispatch to cloud env: - DISPATCH_TOKEN: ${{ secrets.CLOUD_REPO_DISPATCH_TOKEN }} + DISPATCH_TOKEN: ${{ steps.app-token.outputs.token }} RELEASE_TAG: ${{ github.ref_name }} run: | set -euo pipefail if [ -z "${DISPATCH_TOKEN:-}" ]; then - echo "::error::CLOUD_REPO_DISPATCH_TOKEN is required but not set." + echo "::error::App token generation produced an empty token." exit 1 fi