57
57
matrix : ${{ steps.matrix.outputs.matrix }}
58
58
runs-on : [ k8-runners ]
59
59
steps :
60
+ - uses : step-security/harden-runner@v2
61
+ with :
62
+ egress-policy : audit
60
63
- uses : actions/checkout@v4
61
64
- name : Set Matrix
62
65
id : matrix
@@ -83,11 +86,14 @@ jobs:
83
86
matrix : ${{ fromJson(needs.setup-build-matrix.outputs.matrix) }}
84
87
fail-fast : false
85
88
steps :
89
+ - uses : step-security/harden-runner@v2
90
+ with :
91
+ egress-policy : audit
86
92
- uses : actions/checkout@v4
87
93
if : ${{ !inputs.no-build }}
88
94
- uses : docker/login-action@v3
89
95
with :
90
- registry : ${{ vars .REGISTRY }}
96
+ registry : ${{ secrets .REGISTRY }}
91
97
username : ${{ secrets.REGISTRY_USER }}
92
98
password : ${{ secrets.REGISTRY_TOKEN }}
93
99
if : ${{ !inputs.no-build }}
@@ -99,15 +105,18 @@ jobs:
99
105
with :
100
106
group_dir : ${{ inputs.group_dir }}
101
107
env_overrides : ${{ inputs.env_overrides }}
102
- registry : ${{ vars .REGISTRY }}
103
- repo : ${{ vars .REPO }}
108
+ registry : ${{ secrets .REGISTRY }}
109
+ repo : ${{ secrets .REPO }}
104
110
no-push : false
105
111
setup-test :
106
112
needs : [ build-containers ]
107
113
runs-on : [ k8-runners ]
108
114
outputs :
109
115
recipes : ${{ steps.recipes.outputs.RECIPES }}
110
116
steps :
117
+ - uses : step-security/harden-runner@v2
118
+ with :
119
+ egress-policy : audit
111
120
- uses : actions/checkout@v4
112
121
- name : Get Recipes
113
122
id : recipes
@@ -122,18 +131,21 @@ jobs:
122
131
experimental : [true]
123
132
fail-fast : false
124
133
steps :
134
+ - uses : step-security/harden-runner@v2
135
+ with :
136
+ egress-policy : audit
125
137
- uses : actions/checkout@v4
126
138
- uses : docker/login-action@v3
127
139
with :
128
- registry : ${{ vars .REGISTRY }}
140
+ registry : ${{ secrets .REGISTRY }}
129
141
username : ${{ secrets.REGISTRY_USER }}
130
142
password : ${{ secrets.REGISTRY_TOKEN }}
131
143
- name : Test Container Group
132
144
uses : ./test-runner
133
145
with :
134
- mlops_repo : ${{ vars .MLOPS_REPO }}
146
+ mlops_repo : ${{ secrets .MLOPS_REPO }}
135
147
mlops_ref : ${{ github.ref }}
136
148
recipe_dir : ${{ inputs.group_dir }}
137
- registry : ${{ vars .REGISTRY }}
149
+ registry : ${{ secrets .REGISTRY }}
138
150
test_dir : ${{ matrix.recipe }}
139
151
token : ${{ github.token }}
0 commit comments