Skip to content

Give Bitrise one secret and split the docs by audience - #582

Draft
kieran-osgood-shopify wants to merge 1 commit into
kieran-osgood/ejson-run-maestro-e2e-envfrom
kieran-osgood/ejson-ci-and-docs
Draft

Give Bitrise one secret and split the docs by audience#582
kieran-osgood-shopify wants to merge 1 commit into
kieran-osgood/ejson-run-maestro-e2e-envfrom
kieran-osgood/ejson-ci-and-docs

Conversation

@kieran-osgood-shopify

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

Copy link
Copy Markdown
Contributor Author

Bitrise held nine project secrets that had to stay aligned with what the suite
reads. It now holds EJSON_PRIVATE_KEY only. bitrise_ci_helpers installs a pinned
ejson2env, verifies its checksum, writes the key into a keydir, and runs
generate_env_files, so CI decrypts the same committed files a developer does.

The key reaches the keydir through a redirect and the credentials reach envman
through a file, so neither enters an argument list or the build log. Installing
the key is idempotent, because the mode it sets makes the file unwritable.

e2e-execute-browserstack-run builds no app, so it exports the account
credentials itself; every other workflow gets them through a sample app build.

The docs stop describing prompts that no longer exist and say plainly which
audience does what: employees run `dev secrets edit`, external contributors copy
.env.example and keep their file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from a8cf7ad to b2235cf Compare August 5, 2026 12:33
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from a2af77b to 22eb2d4 Compare August 5, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant