Skip to content

Give Bitrise one secret and split the docs by audience - #582

Draft
kieran-osgood-shopify wants to merge 4 commits into
kieran-osgood/ejson-run-maestro-e2e-envfrom
kieran-osgood/ejson-ci-and-docs
Draft

Give Bitrise one secret and split the docs by audience#582
kieran-osgood-shopify wants to merge 4 commits into
kieran-osgood/ejson-run-maestro-e2e-envfrom
kieran-osgood/ejson-ci-and-docs

Conversation

@kieran-osgood-shopify

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

kieran-osgood-shopify commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from 76f072a to ce17650 Compare August 5, 2026 11:06
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from bebc4d0 to 1dc2560 Compare August 5, 2026 11:06
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from ce17650 to 88b6724 Compare August 5, 2026 11:35
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch 2 times, most recently from 39b95df to a8cf7ad Compare August 5, 2026 11:45
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from 88b6724 to a2af77b Compare August 5, 2026 11:45
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from a8cf7ad to b2235cf Compare August 5, 2026 12:33
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from a2af77b to 22eb2d4 Compare August 5, 2026 12:33
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from b2235cf to 84842c5 Compare August 6, 2026 15:48
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch 3 times, most recently from f21da07 to cb34ba1 Compare August 7, 2026 11:05
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch 2 times, most recently from bdd7527 to 23d353a Compare August 7, 2026 11:28
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch 2 times, most recently from b76b5f1 to 4d50b40 Compare August 7, 2026 13:51
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch 2 times, most recently from 3466ca1 to ef1f3ac Compare August 7, 2026 14:15
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch 2 times, most recently from 8b654b6 to eebdd2b Compare August 7, 2026 15:41
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from ef1f3ac to 9b59e1e Compare August 7, 2026 15:41
Bitrise held nine project secrets that had to stay aligned with what the suite
reads. It now holds EJSON_PRIVATE_KEY only. bitrise_ci_helpers installs a pinned
ejson2env, verifies its checksum, writes the key into a keydir, and runs
generate_env_files, so CI decrypts the same committed files a developer does.

The key reaches the keydir through a redirect and the credentials reach envman
through a file, so neither enters an argument list or the build log. Installing
the key is idempotent, because the mode it sets makes the file unwritable.

e2e-execute-browserstack-run builds no app, so it exports the account
credentials itself; every other workflow gets them through a sample app build.

The docs stop describing prompts that no longer exist and say plainly which
audience does what: employees run `dev secrets edit`, external contributors copy
.env.example and keep their file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
kieran-osgood-shopify and others added 3 commits August 10, 2026 10:06
The E2E suite read its own e2e/.env for Maestro, but the sample apps it drives
were still configured from the repo-root .env. That file comes from
config/secrets/demo.ejson, which a developer may point at their own shop, so a
suite run tested whichever store happened to be set up for manual work.

scripts/setup_storefront_env takes --env-file, and e2e_configure_storefront
passes e2e/.env. The four generated platform config files are shared, so the
last run still wins, but nothing on the E2E path reads the demo store now.

It also takes --ignore-generated. The script reads the files it generates as a
value source, so a developer who lost .env keeps their store. That inheritance
is wrong for the suite: on a workspace that already built the demo app those
files hold the demo store and a Canadian address. e2e.ejson carries no address,
so the United States defaults decide it instead.

That last part is flake B2 returning by a new route. The original fix relied on
CI holding no address values at all, which encrypted config changed. Two tests
hold it now: scripts/test_setup_storefront_env covers the flag, and the new
e2e/scripts/test_bitrise_ci_helpers asserts the argv the CI path builds.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-ci-and-docs branch from eebdd2b to a2b3bad Compare August 10, 2026 09:08
@kieran-osgood-shopify
kieran-osgood-shopify force-pushed the kieran-osgood/ejson-run-maestro-e2e-env branch from 9b59e1e to 8d003d5 Compare August 10, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant