feat: Add GitHub token support from Vault for changelog fetching
All checks were successful
Code Quality & Security Scan / TFLint (push) Successful in 24s
Code Quality & Security Scan / Terraform Destroy (push) Has been skipped
Code Quality & Security Scan / Tfsec Security Scan (push) Successful in 34s
Code Quality & Security Scan / Checkov Security Scan (push) Successful in 37s
Code Quality & Security Scan / Terraform Validate (push) Successful in 40s
Code Quality & Security Scan / SonarQube Scan (push) Successful in 43s
Code Quality & Security Scan / Terraform Plan (push) Successful in 1m26s
Code Quality & Security Scan / Terraform Apply (push) Successful in 2m6s

This commit is contained in:
Patrick de Ruiter 2025-11-29 12:42:51 +01:00
parent fe030ac335
commit 11a79e5b3e
Signed by: pderuiter
GPG Key ID: 5EBA7F21CF583321

View File

@ -40,7 +40,8 @@ resource "docker_container" "renovate" {
"RENOVATE_AUTODISCOVER=${var.renovate_autodiscover}",
"LOG_LEVEL=${var.log_level}"
],
var.github_com_token != "" ? ["GITHUB_COM_TOKEN=${var.github_com_token}"] : [],
# GitHub token: prefer Vault, fall back to variable
coalesce(try(data.vault_generic_secret.renovate.data["github_token"], ""), var.github_com_token) != "" ? ["GITHUB_COM_TOKEN=${coalesce(try(data.vault_generic_secret.renovate.data["github_token"], ""), var.github_com_token)}"] : [],
var.extra_env_vars
)