Give Bitrise one secret and split the docs by audience - #582
Draft
kieran-osgood-shopify wants to merge 4 commits into
Draft
Give Bitrise one secret and split the docs by audience#582kieran-osgood-shopify wants to merge 4 commits into
kieran-osgood-shopify wants to merge 4 commits into
Conversation
This was referenced Aug 5, 2026
Contributor
Author
This was referenced Aug 5, 2026
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:06
76f072a to
ce17650
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 5, 2026 11:06
bebc4d0 to
1dc2560
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:35
ce17650 to
88b6724
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
2 times, most recently
from
August 5, 2026 11:45
39b95df to
a8cf7ad
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:45
88b6724 to
a2af77b
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 5, 2026 12:33
a8cf7ad to
b2235cf
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 12:33
a2af77b to
22eb2d4
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 6, 2026 15:48
b2235cf to
84842c5
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
3 times, most recently
from
August 7, 2026 11:05
f21da07 to
cb34ba1
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
2 times, most recently
from
August 7, 2026 11:28
bdd7527 to
23d353a
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
2 times, most recently
from
August 7, 2026 13:51
b76b5f1 to
4d50b40
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
2 times, most recently
from
August 7, 2026 14:15
3466ca1 to
ef1f3ac
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
2 times, most recently
from
August 7, 2026 15:41
8b654b6 to
eebdd2b
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 7, 2026 15:41
ef1f3ac to
9b59e1e
Compare
Bitrise held nine project secrets that had to stay aligned with what the suite reads. It now holds EJSON_PRIVATE_KEY only. bitrise_ci_helpers installs a pinned ejson2env, verifies its checksum, writes the key into a keydir, and runs generate_env_files, so CI decrypts the same committed files a developer does. The key reaches the keydir through a redirect and the credentials reach envman through a file, so neither enters an argument list or the build log. Installing the key is idempotent, because the mode it sets makes the file unwritable. e2e-execute-browserstack-run builds no app, so it exports the account credentials itself; every other workflow gets them through a sample app build. The docs stop describing prompts that no longer exist and say plainly which audience does what: employees run `dev secrets edit`, external contributors copy .env.example and keep their file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
The E2E suite read its own e2e/.env for Maestro, but the sample apps it drives were still configured from the repo-root .env. That file comes from config/secrets/demo.ejson, which a developer may point at their own shop, so a suite run tested whichever store happened to be set up for manual work. scripts/setup_storefront_env takes --env-file, and e2e_configure_storefront passes e2e/.env. The four generated platform config files are shared, so the last run still wins, but nothing on the E2E path reads the demo store now. It also takes --ignore-generated. The script reads the files it generates as a value source, so a developer who lost .env keeps their store. That inheritance is wrong for the suite: on a workspace that already built the demo app those files hold the demo store and a Canadian address. e2e.ejson carries no address, so the United States defaults decide it instead. That last part is flake B2 returning by a new route. The original fix relied on CI holding no address values at all, which encrypted config changed. Two tests hold it now: scripts/test_setup_storefront_env covers the flag, and the new e2e/scripts/test_bitrise_ci_helpers asserts the argv the CI path builds. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 10, 2026 09:08
eebdd2b to
a2b3bad
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 10, 2026 09:08
9b59e1e to
8d003d5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What changes are you making?
How to test
Before you merge
Important
platforms/swift/README.mdand/orplatforms/android/README.md)Releasing a new Swift version?
ShopifyCheckoutKit.podspecplatforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swiftplatforms/swift/README.md(major version only)Releasing a new Embedded Checkout Protocol version?
embeddedCheckoutProtocolAndroidinplatforms/android/gradle/libs.versions.tomlprotocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.apiif the public API changedReleasing a new Android version?
checkoutKitAndroidinplatforms/android/gradle/libs.versions.tomlplatforms/android/README.mdTip
See the Contributing documentation for the full release process per platform.