Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
PR-controlled code receives production artifact-writer privileges, and unrelated label updates cause redundant builds.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds label-triggered preview image builds for FxA preview environments.
Changes:
- Builds
fxa-monofrom labeled PR heads. - Pushes SHA-tagged images to GAR.
- Excludes fork-based PRs.
File summaries
| File | Description |
|---|---|
.github/workflows/docker-preview.yml |
Defines the preview image workflow. |
Review details
Suppressed comments (1)
.github/workflows/docker-preview.yml:26
- This privileged job executes scripts and a Dockerfile from the PR head while holding
id-token: write, so same-repository PR code can request the OIDC token itself and impersonate the productionartifact-writer, potentially overwriting release artifacts infxa-prod. Fork exclusion does not isolate untrusted or compromised collaborator branches. Build the PR image in an unprivileged job, then publish the resulting OCI artifact from a job that never executes PR-controlled code, ideally with a preview-only repository and service account.
id-token: write
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced (auto)
Note
Copilot is running an experiment and ran this review at Balanced.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+19
to
+21
| if: > | ||
| contains(github.event.pull_request.labels.*.name, 'preview') && | ||
| github.event.pull_request.head.repo.full_name == github.repository |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a workflow that builds
fxa-monoand pushes it to GAR tagged with the first 10 chars of the PR head sha, for pull requests labeledpreview. This is the image the MozCloud preview environment ApplicationSet deploys (image.tag = head_sha | trunc 10).Mirrors the existing
docker.ymlrelease build (same pinned actions, WIF auth, and Dockerfile), minus the Docker Hub push and tag verification. Fork PRs are excluded.One thing to verify on merge: the
buildenvironment's protection rules must allowpull_requestruns, or the job will hang on approval.Part of enabling FxA preview environments: