From d120a82e6909cc2cebe74646ad31718d65d894c4 Mon Sep 17 00:00:00 2001 From: CrazyMax <1951866+crazy-max@users.noreply.github.com> Date: Mon, 5 Oct 2026 12:43:57 +0200 Subject: [PATCH] support Docker Hub OIDC authentication scopes Pass the optional registry identity scope to Docker Hub OIDC login steps in the build, bake, and verification workflows. Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com> --- .github/workflows/bake.yml | 2 ++ .github/workflows/build.yml | 2 ++ .github/workflows/setup-registry-identities.yml | 6 ++++++ .github/workflows/verify.yml | 1 + README.md | 13 +++++++------ 5 files changed, 18 insertions(+), 6 deletions(-) diff --git a/.github/workflows/bake.yml b/.github/workflows/bake.yml index 5f5bfd52..a6c07bb2 100644 --- a/.github/workflows/bake.yml +++ b/.github/workflows/bake.yml @@ -768,6 +768,7 @@ jobs: registry-auth: | - registry: ${{ needs.registry-identities.outputs.dockerhub-oidc-registry }} username: ${{ needs.registry-identities.outputs.dockerhub-oidc-username }} + scope: ${{ needs.registry-identities.outputs.dockerhub-oidc-scope }} - name: Authenticate to Azure if: ${{ needs.registry-identities.outputs.azure-acr-enabled == 'true' }} @@ -1243,6 +1244,7 @@ jobs: registry-auth: | - registry: ${{ needs.registry-identities.outputs.dockerhub-oidc-registry }} username: ${{ needs.registry-identities.outputs.dockerhub-oidc-username }} + scope: ${{ needs.registry-identities.outputs.dockerhub-oidc-scope }} - name: Authenticate to Azure if: ${{ inputs.push && inputs.output == 'image' && needs.registry-identities.outputs.azure-acr-enabled == 'true' }} diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5f4a4846..0e80b7d3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -695,6 +695,7 @@ jobs: registry-auth: | - registry: ${{ needs.registry-identities.outputs.dockerhub-oidc-registry }} username: ${{ needs.registry-identities.outputs.dockerhub-oidc-username }} + scope: ${{ needs.registry-identities.outputs.dockerhub-oidc-scope }} - name: Authenticate to Azure if: ${{ needs.registry-identities.outputs.azure-acr-enabled == 'true' }} @@ -1128,6 +1129,7 @@ jobs: registry-auth: | - registry: ${{ needs.registry-identities.outputs.dockerhub-oidc-registry }} username: ${{ needs.registry-identities.outputs.dockerhub-oidc-username }} + scope: ${{ needs.registry-identities.outputs.dockerhub-oidc-scope }} - name: Authenticate to Azure if: ${{ inputs.push && inputs.output == 'image' && needs.registry-identities.outputs.azure-acr-enabled == 'true' }} diff --git a/.github/workflows/setup-registry-identities.yml b/.github/workflows/setup-registry-identities.yml index b8473525..345ecfe4 100644 --- a/.github/workflows/setup-registry-identities.yml +++ b/.github/workflows/setup-registry-identities.yml @@ -55,6 +55,9 @@ on: dockerhub-oidc-connection-id: description: "Docker Hub OIDC connection ID" value: ${{ jobs.setup-registry-identities.outputs.dockerhub-oidc-connection-id }} + dockerhub-oidc-scope: + description: "Docker Hub authentication scope" + value: ${{ jobs.setup-registry-identities.outputs.dockerhub-oidc-scope }} azure-acr-enabled: description: "Whether an Azure ACR registry identity was configured" value: ${{ jobs.setup-registry-identities.outputs.azure-acr-enabled }} @@ -114,6 +117,7 @@ jobs: dockerhub-oidc-registry: ${{ steps.validate.outputs.dockerhub-oidc-registry }} dockerhub-oidc-username: ${{ steps.validate.outputs.dockerhub-oidc-username }} dockerhub-oidc-connection-id: ${{ steps.validate.outputs.dockerhub-oidc-connection-id }} + dockerhub-oidc-scope: ${{ steps.validate.outputs.dockerhub-oidc-scope }} azure-acr-enabled: ${{ steps.validate.outputs.azure-acr-enabled }} azure-acr-registry: ${{ steps.validate.outputs.azure-acr-registry }} azure-acr-client-id: ${{ steps.validate.outputs.azure-acr-client-id }} @@ -186,6 +190,7 @@ jobs: core.setOutput('dockerhub-oidc-registry', ''); core.setOutput('dockerhub-oidc-username', ''); core.setOutput('dockerhub-oidc-connection-id', ''); + core.setOutput('dockerhub-oidc-scope', ''); core.setOutput('azure-acr-enabled', 'false'); core.setOutput('azure-acr-registry', ''); core.setOutput('azure-acr-client-id', ''); @@ -245,6 +250,7 @@ jobs: core.setOutput('dockerhub-oidc-registry', dockerhubOidc?.registry || ''); core.setOutput('dockerhub-oidc-username', dockerhubOidc?.username || ''); core.setOutput('dockerhub-oidc-connection-id', dockerhubOidc?.connectionID || ''); + core.setOutput('dockerhub-oidc-scope', dockerhubOidc?.scope || ''); core.setOutput('azure-acr-enabled', azureAcr ? 'true' : 'false'); core.setOutput('azure-acr-registry', azureAcr?.registry || ''); core.setOutput('azure-acr-client-id', azureAcr?.clientId || ''); diff --git a/.github/workflows/verify.yml b/.github/workflows/verify.yml index 7a8f3be8..76f0f1c6 100644 --- a/.github/workflows/verify.yml +++ b/.github/workflows/verify.yml @@ -163,6 +163,7 @@ jobs: registry-auth: | - registry: ${{ needs.registry-identities.outputs.dockerhub-oidc-registry }} username: ${{ needs.registry-identities.outputs.dockerhub-oidc-username }} + scope: ${{ needs.registry-identities.outputs.dockerhub-oidc-scope }} - name: Authenticate to Azure if: ${{ steps.vars.outputs.signed == 'true' && steps.vars.outputs.output-type == 'image' && needs.registry-identities.outputs.azure-acr-enabled == 'true' }} diff --git a/README.md b/README.md index 12664efb..228b721c 100644 --- a/README.md +++ b/README.md @@ -538,12 +538,13 @@ jobs: connection_id: 123e4567-e89b-42d3-a456-426614174000 ``` -| Name | Type | Required | Description | -|-----------------|--------|----------|-----------------------------------------------------------------------------| -| `type` | String | Yes | Registry identity provider type. Must be `dockerhub`. | -| `registry` | String | No | Registry hostname passed to `docker/login-action`. Defaults to `docker.io`. | -| `username` | String | Yes | Docker Hub username or organization passed to `docker/login-action`. | -| `connection_id` | String | Yes | Docker Hub OIDC connection ID passed to `docker/login-action` in each job. | +| Name | Type | Required | Description | +|-----------------|--------|----------|-----------------------------------------------------------------------------------------------------------------------------------| +| `type` | String | Yes | Registry identity provider type. Must be `dockerhub`. | +| `registry` | String | No | Registry hostname passed to `docker/login-action`. Defaults to `docker.io`. | +| `username` | String | Yes | Docker Hub username or organization passed to `docker/login-action`. | +| `connection_id` | String | Yes | Docker Hub OIDC connection ID passed to `docker/login-action` in each job. | +| `scope` | String | No | [Authentication scope](https://github.com/docker/login-action#set-scopes-for-the-authentication-token) for `docker/login-action`. | The workflow mints the Docker Hub access token inside each reusable workflow job that needs Docker Hub registry access. The token is not accepted as an