All questions

Running the Croct CLI in CI keeps asking me to log in, how do I automate it?

Asked by devops_kate on

Ddevops_kate

Trying to add a Croct CLI step to our pipeline and the step stops dead waiting for an interactive login. That obviously does not work in a headless runner, it just hangs until the job times out.

What is the non-interactive way to authenticate the CLI in an automated run? I do not want a human clicking through a login as part of a deploy

Was this helpful?

2 answers

PRPriya Raman

The login and logout commands are for interactive use, so they are never going to fit an unattended pipeline. What you want instead is an API key.

Run npx croct create api-key to generate one, then feed it to the CLI in CI so the step does not try to log in at all. The HTTP API authenticates with the X-Api-Key header, so a key is exactly what a headless environment is meant to use, no browser round trip involved. There is more context on how the key gets used server-side in fetchContent works locally but returns auth errors in prod.

Was this helpful?
Ddooley

One thing to do when you create the key: scope it to only the permissions the CI step actually needs. If the step just regenerates types and reads config it does not need broad access, so do not hand it more than the job requires. Keeps the blast radius small if the key ever leaks from the runner.

Was this helpful?
Ddevops_kate

created a scoped key, pipeline runs clean now with no login prompt. that was the whole blocker

Still have questions?