GitHub Actions
This is a GitHub Actions workflow that exchanges GitHub OIDC for an Amendable token and pushes over HTTPS.
Save this as .github/workflows/amendable-git.yml in your GitHub repository.
Before the first run
Section titled “Before the first run”Create a matching OIDC trust rule. See OIDC for machines.
Set GitHub Actions variables on that repository:
AMENDABLE_OWNER: your Amendable usernameAMENDABLE_REPO: repository name (create it first)AMENDABLE_AUDIENCE:amendable:<your-user-uuid>fromGET /v1/oidc-trust-rules/setup
The job requests id-token: write, exchanges the GitHub OIDC token at POST /v1/oidc/token, then clones and pushes https://amendable.io/r/<owner>/<repo>.git. Git password is the short-lived Amendable token.
Workflow
Section titled “Workflow”# Exchange a GitHub Actions OIDC token for an Amendable access token,# then clone and push over HTTPS.## Create an Amendable OIDC trust rule first:# issuer: https://token.actions.githubusercontent.com# audience: amendable:<your-user-uuid># subject: repo:YOUR_ORG/YOUR_REPO:ref:refs/heads/main# grants: GIT_HTTP_READ, GIT_HTTP_WRITE, API_REPOS_WRITE
name: Amendable git
on: workflow_dispatch:
permissions: id-token: write contents: read
jobs: push-to-amendable: runs-on: ubuntu-latest env: AMENDABLE_OWNER: ${{ vars.AMENDABLE_OWNER }} AMENDABLE_REPO: ${{ vars.AMENDABLE_REPO }} AMENDABLE_AUDIENCE: ${{ vars.AMENDABLE_AUDIENCE }} steps: - uses: actions/checkout@v4
- name: Mint GitHub OIDC token id: oidc run: | TOKEN=$(curl -sS -H "Authorization: Bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \ "${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=${AMENDABLE_AUDIENCE}" \ | python3 -c 'import json,sys; print(json.load(sys.stdin)["value"])') echo "::add-mask::$TOKEN" echo "id_token=$TOKEN" >> "$GITHUB_OUTPUT"
- name: Exchange for Amendable access token id: amendable run: | TOKEN=$(curl -sS -X POST "https://api.amendable.io/v1/oidc/token" \ -H "Content-Type: application/json" \ -d "{\"id_token\": \"${{ steps.oidc.outputs.id_token }}\"}" \ | python3 -c 'import json,sys; print(json.load(sys.stdin)["token"])') echo "::add-mask::$TOKEN" echo "token=$TOKEN" >> "$GITHUB_OUTPUT"
- name: Clone, commit, push env: AMENDABLE_TOKEN: ${{ steps.amendable.outputs.token }} run: | git config --global user.email "ci@example.com" git config --global user.name "GitHub Actions" git clone "https://${AMENDABLE_OWNER}:${AMENDABLE_TOKEN}@amendable.io/r/${AMENDABLE_OWNER}/${AMENDABLE_REPO}.git" work cd work date -u > last-run.txt git add last-run.txt git commit -m "chore: record CI run" || true git push origin HEAD:main