diff --git a/.github/get-sonatype-credentials.sh b/.github/get-sonatype-credentials.sh index f1660f509d5..b84263784d7 100755 --- a/.github/get-sonatype-credentials.sh +++ b/.github/get-sonatype-credentials.sh @@ -1,8 +1,8 @@ #!/bin/bash # Script to retrieve Sonatype credentials from AWS Secrets Manager -SONATYPE_USERNAME=$(aws secretsmanager get-secret-value --secret-id maven-snapshots-username --query SecretString --output text) -SONATYPE_PASSWORD=$(aws secretsmanager get-secret-value --secret-id maven-snapshots-password --query SecretString --output text) +SONATYPE_USERNAME=op://opensearch-infra-secrets/maven-central-portal-credentials/username +SONATYPE_PASSWORD=op://opensearch-infra-secrets/maven-central-portal-credentials/password echo "::add-mask::$SONATYPE_USERNAME" echo "::add-mask::$SONATYPE_PASSWORD" echo "SONATYPE_USERNAME=$SONATYPE_USERNAME" >> $GITHUB_ENV diff --git a/.github/workflows/link-checker.yml b/.github/workflows/link-checker.yml index 42c8fd35c81..12555907e4e 100644 --- a/.github/workflows/link-checker.yml +++ b/.github/workflows/link-checker.yml @@ -18,7 +18,7 @@ jobs: id: lychee uses: lycheeverse/lychee-action@master with: - args: --accept=200,403,429,999 "./**/*.html" "./**/*.md" "./**/*.txt" --exclude "https://aws.oss.sonatype.*|http://localhost.*|https://localhost|https://odfe-node1:9200/|https://community.tableau.com/docs/DOC-17978|.*family.zzz|opensearch*|.*@amazon.com|.*email.com|.*@github.com|http://timestamp.verisign.com/scripts/timstamp.dll" + args: --accept=200,403,429,999 "./**/*.html" "./**/*.md" "./**/*.txt" --exclude "https://aws.oss.sonatype.*|https://central.sonatype.*|http://localhost.*|https://localhost|https://odfe-node1:9200/|https://community.tableau.com/docs/DOC-17978|.*family.zzz|opensearch*|.*@amazon.com|.*email.com|.*@github.com|http://timestamp.verisign.com/scripts/timstamp.dll" env: GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}} - name: Fail if there were link errors diff --git a/.github/workflows/maven-publish.yml b/.github/workflows/maven-publish.yml index 019ff7384eb..1645cd4501d 100644 --- a/.github/workflows/maven-publish.yml +++ b/.github/workflows/maven-publish.yml @@ -9,7 +9,7 @@ on: - 2.* env: - SNAPSHOT_REPO_URL: https://aws.oss.sonatype.org/content/repositories/snapshots/ + SNAPSHOT_REPO_URL: https://central.sonatype.com/repository/maven-snapshots/ jobs: build-and-publish-snapshots: @@ -28,15 +28,15 @@ jobs: distribution: temurin # Temurin is a distribution of adoptium java-version: 21 - uses: actions/checkout@v3 - - uses: aws-actions/configure-aws-credentials@v1.7.0 + - name: Load secret + uses: 1password/load-secrets-action@v2 with: - role-to-assume: ${{ secrets.PUBLISH_SNAPSHOTS_ROLE }} - aws-region: us-east-1 - - - name: get credentials - run: | - # Get credentials for publishing - .github/get-sonatype-credentials.sh + # Export loaded secrets as environment variables + export-env: true + env: + OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }} + SONATYPE_USERNAME: op://opensearch-infra-secrets/maven-central-portal-credentials/username + SONATYPE_PASSWORD: op://opensearch-infra-secrets/maven-central-portal-credentials/password - name: publish snapshots to maven run: | diff --git a/.github/workflows/publish-async-query-core.yml b/.github/workflows/publish-async-query-core.yml index 3347857a0ae..ef721a8d7c2 100644 --- a/.github/workflows/publish-async-query-core.yml +++ b/.github/workflows/publish-async-query-core.yml @@ -18,7 +18,7 @@ concurrency: cancel-in-progress: false env: - SNAPSHOT_REPO_URL: https://aws.oss.sonatype.org/content/repositories/snapshots/ + SNAPSHOT_REPO_URL: https://central.sonatype.com/repository/maven-snapshots/ COMMIT_MAP_FILENAME: commit-history-async-query-core.json jobs: @@ -40,15 +40,15 @@ jobs: - uses: actions/checkout@v3 - - uses: aws-actions/configure-aws-credentials@v1.7.0 + - name: Load secret + uses: 1password/load-secrets-action@v2 with: - role-to-assume: ${{ secrets.PUBLISH_SNAPSHOTS_ROLE }} - aws-region: us-east-1 - - - name: Setup publishing credentials - id: creds - run: | - .github/get-sonatype-credentials.sh + # Export loaded secrets as environment variables + export-env: true + env: + OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }} + SONATYPE_USERNAME: op://opensearch-infra-secrets/maven-central-portal-credentials/username + SONATYPE_PASSWORD: op://opensearch-infra-secrets/maven-central-portal-credentials/password - name: Set commit ID id: set_commit diff --git a/.github/workflows/publish-grammar-files.yml b/.github/workflows/publish-grammar-files.yml index e871b977238..5b2d414c5f1 100644 --- a/.github/workflows/publish-grammar-files.yml +++ b/.github/workflows/publish-grammar-files.yml @@ -19,7 +19,7 @@ concurrency: cancel-in-progress: false env: - SNAPSHOT_REPO_URL: https://aws.oss.sonatype.org/content/repositories/snapshots/ + SNAPSHOT_REPO_URL: https://central.sonatype.com/repository/maven-snapshots/ COMMIT_MAP_FILENAME: commit-history-language-grammar.json jobs: @@ -44,15 +44,15 @@ jobs: - uses: actions/checkout@v3 - - uses: aws-actions/configure-aws-credentials@v1.7.0 + - name: Load secret + uses: 1password/load-secrets-action@v2 with: - role-to-assume: ${{ secrets.PUBLISH_SNAPSHOTS_ROLE }} - aws-region: us-east-1 - - - name: Setup publishing credentials - id: creds - run: | - .github/get-sonatype-credentials.sh + # Export loaded secrets as environment variables + export-env: true + env: + OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }} + SONATYPE_USERNAME: op://opensearch-infra-secrets/maven-central-portal-credentials/username + SONATYPE_PASSWORD: op://opensearch-infra-secrets/maven-central-portal-credentials/password - name: Set version id: set_version diff --git a/integ-test/build.gradle b/integ-test/build.gradle index aea61ca5a17..c8da4378e49 100644 --- a/integ-test/build.gradle +++ b/integ-test/build.gradle @@ -70,7 +70,7 @@ ext { noticeFile = rootProject.file('NOTICE') getSecurityPluginDownloadLink = { -> - var repo = "https://aws.oss.sonatype.org/content/repositories/snapshots/org/opensearch/plugin/" + + var repo = "https://central.sonatype.com/repository/maven-snapshots/org/opensearch/plugin/" + "opensearch-security/$opensearch_build_snapshot/" var metadataFile = Paths.get(projectDir.toString(), "build", "maven-metadata.xml").toAbsolutePath().toFile() download.run { diff --git a/plugin/build.gradle b/plugin/build.gradle index ddf0227bb0e..e0b9f4f555a 100644 --- a/plugin/build.gradle +++ b/plugin/build.gradle @@ -82,7 +82,7 @@ publishing { repositories { maven { name = "Snapshots" // optional target repository name - url = "https://aws.oss.sonatype.org/content/repositories/snapshots" + url = "https://central.sonatype.com/repository/maven-snapshots/" credentials { username "$System.env.SONATYPE_USERNAME" password "$System.env.SONATYPE_PASSWORD"