Map GCB trigger subs to environment vars (#3208)

Also quote the variables.

Passing the variables through the "env" block means that we avoid any
situations where the characters trigger some evaluation.

https://docs.cloud.google.com/build/docs/configuring-builds/substitute-variable-values

G.4 number 2

b/535251126
This commit is contained in:
gbrodman
2026-08-14 16:47:25 +00:00
committed by GitHub
parent 59867a97d2
commit 84811d5624
5 changed files with 71 additions and 40 deletions
+3 -1
View File
@@ -17,6 +17,8 @@ steps:
# Check out the internal repo.
- name: 'gcr.io/cloud-builders/git:latest'
entrypoint: /bin/bash
env:
- '_INTERNAL_REPO_URL=${_INTERNAL_REPO_URL}'
args:
- -c
- |
@@ -26,7 +28,7 @@ steps:
ln -s /usr/bin/python3 /usr/bin/python
fi
./gcompute-tools/git-cookie-authdaemon
git clone ${_INTERNAL_REPO_URL} nomulus-internal
git clone "$_INTERNAL_REPO_URL" nomulus-internal
# Download and decrypt the nomulus tool credential
- name: 'gcr.io/$PROJECT_ID/builder:live'
entrypoint: /bin/bash