Skip to content

GitHub Actions

This is a GitHub Actions workflow that exchanges GitHub OIDC for an Amendable token and pushes over HTTPS.

Save this as .github/workflows/amendable-git.yml in your GitHub repository.

Create a matching OIDC trust rule. See OIDC for machines.

Set GitHub Actions variables on that repository:

  • AMENDABLE_OWNER: your Amendable username
  • AMENDABLE_REPO: repository name (create it first)
  • AMENDABLE_AUDIENCE: amendable:<your-user-uuid> from GET /v1/oidc-trust-rules/setup

The job requests id-token: write, exchanges the GitHub OIDC token at POST /v1/oidc/token, then clones and pushes https://amendable.io/r/<owner>/<repo>.git. Git password is the short-lived Amendable token.

.github/workflows/amendable-git.yml
# Exchange a GitHub Actions OIDC token for an Amendable access token,
# then clone and push over HTTPS.
#
# Create an Amendable OIDC trust rule first:
# issuer: https://token.actions.githubusercontent.com
# audience: amendable:<your-user-uuid>
# subject: repo:YOUR_ORG/YOUR_REPO:ref:refs/heads/main
# grants: GIT_HTTP_READ, GIT_HTTP_WRITE, API_REPOS_WRITE
name: Amendable git
on:
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
push-to-amendable:
runs-on: ubuntu-latest
env:
AMENDABLE_OWNER: ${{ vars.AMENDABLE_OWNER }}
AMENDABLE_REPO: ${{ vars.AMENDABLE_REPO }}
AMENDABLE_AUDIENCE: ${{ vars.AMENDABLE_AUDIENCE }}
steps:
- uses: actions/checkout@v4
- name: Mint GitHub OIDC token
id: oidc
run: |
TOKEN=$(curl -sS -H "Authorization: Bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=${AMENDABLE_AUDIENCE}" \
| python3 -c 'import json,sys; print(json.load(sys.stdin)["value"])')
echo "::add-mask::$TOKEN"
echo "id_token=$TOKEN" >> "$GITHUB_OUTPUT"
- name: Exchange for Amendable access token
id: amendable
run: |
TOKEN=$(curl -sS -X POST "https://api.amendable.io/v1/oidc/token" \
-H "Content-Type: application/json" \
-d "{\"id_token\": \"${{ steps.oidc.outputs.id_token }}\"}" \
| python3 -c 'import json,sys; print(json.load(sys.stdin)["token"])')
echo "::add-mask::$TOKEN"
echo "token=$TOKEN" >> "$GITHUB_OUTPUT"
- name: Clone, commit, push
env:
AMENDABLE_TOKEN: ${{ steps.amendable.outputs.token }}
run: |
git config --global user.email "ci@example.com"
git config --global user.name "GitHub Actions"
git clone "https://${AMENDABLE_OWNER}:${AMENDABLE_TOKEN}@amendable.io/r/${AMENDABLE_OWNER}/${AMENDABLE_REPO}.git" work
cd work
date -u > last-run.txt
git add last-run.txt
git commit -m "chore: record CI run" || true
git push origin HEAD:main