This repository was archived by the owner on Jul 7, 2026. It is now read-only.
Repository navigation
100 lines (91 loc) · 3.42 KB
/
Copy pathxcode-cloud-probe.yml
File metadata and controls
100 lines (91 loc) · 3.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
name: Xcode Cloud Probe
# On-demand diagnostic: hits the Xcode Cloud read-only endpoints with the
# existing ASC API key and reports what we can see. Run this from the
# Actions tab → "Xcode Cloud Probe" → "Run workflow" to find out:
#
# - Is Xcode Cloud terms acceptance done on this team account?
# - Is the OffScript app provisioned for Xcode Cloud?
# - What workflows already exist for it?
#
# Output guides next steps. If terms aren't accepted, you'll see the one
# manual URL to click; everything else is API-driven.
on:
workflow_dispatch:
inputs:
command:
description: "Subcommand"
required: false
default: "probe"
type: choice
options: [probe, inspect, reconfigure-dryrun, reconfigure-apply, start-build, build-run]
workflow_id:
description: "Workflow UUID (required for inspect/reconfigure/start-build)"
required: false
type: string
build_run_id:
description: "Build run UUID (required for build-run)"
required: false
type: string
permissions:
contents: read
jobs:
probe:
name: Xcode Cloud probe
runs-on: ubuntu-latest
timeout-minutes: 5
env:
ASC_BUNDLE_ID: com.offscript.app
ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
ASC_KEY_TYPE: team
steps:
- uses: actions/checkout@v4
- name: Install ASC script deps
run: |
set -euo pipefail
python3 -m pip install --quiet --user PyJWT cryptography requests
- name: Materialize ASC API key
run: |
set -euo pipefail
umask 077
ASC_KEY_PATH="$RUNNER_TEMP/AuthKey.p8"
printf '%s' "$ASC_KEY_P8_BASE64" | base64 --decode > "$ASC_KEY_PATH"
test -s "$ASC_KEY_PATH"
echo "ASC_KEY_PATH=$ASC_KEY_PATH" >> "$GITHUB_ENV"
env:
ASC_KEY_P8_BASE64: ${{ secrets.ASC_KEY_P8_BASE64 }}
- name: Probe / inspect / start build
env:
CMD: ${{ github.event.inputs.command || 'probe' }}
WF_ID: ${{ github.event.inputs.workflow_id }}
BR_ID: ${{ github.event.inputs.build_run_id }}
run: |
set -euo pipefail
case "$CMD" in
probe)
scripts/app_store_connect.py xcode-cloud probe
;;
inspect)
test -n "${WF_ID:-}" || { echo "workflow_id input required"; exit 1; }
scripts/app_store_connect.py xcode-cloud inspect "$WF_ID"
;;
reconfigure-dryrun)
test -n "${WF_ID:-}" || { echo "workflow_id input required"; exit 1; }
scripts/app_store_connect.py xcode-cloud reconfigure "$WF_ID" --testflight
;;
reconfigure-apply)
test -n "${WF_ID:-}" || { echo "workflow_id input required"; exit 1; }
scripts/app_store_connect.py xcode-cloud reconfigure "$WF_ID" --testflight --apply
;;
start-build)
test -n "${WF_ID:-}" || { echo "workflow_id input required"; exit 1; }
scripts/app_store_connect.py xcode-cloud start-build "$WF_ID"
;;
build-run)
test -n "${BR_ID:-}" || { echo "build_run_id input required"; exit 1; }
scripts/app_store_connect.py xcode-cloud build-run "$BR_ID"
;;
*)
echo "Unknown command: $CMD"; exit 1
;;
esac