|
| 1 | +--- |
| 2 | +title: 'CI/CD Authentication' |
| 3 | +description: 'Authenticate Suga CLI in CI/CD pipelines using Personal Access Tokens' |
| 4 | +--- |
| 5 | + |
| 6 | +## Overview |
| 7 | + |
| 8 | +To use the Suga CLI in automated CI/CD environments, you need to authenticate without interactive login prompts. Personal Access Tokens provide a secure way to authenticate the CLI in: |
| 9 | + |
| 10 | +- GitHub Actions |
| 11 | +- GitLab CI |
| 12 | +- CircleCI |
| 13 | +- Jenkins |
| 14 | +- BitBucket Pipelines |
| 15 | +- Any CI/CD platform |
| 16 | + |
| 17 | +## Quick Start |
| 18 | + |
| 19 | +Set the `SUGA_ACCESS_TOKEN` environment variable with your Personal Access Token: |
| 20 | + |
| 21 | +```bash |
| 22 | +export SUGA_ACCESS_TOKEN="your-token-here" |
| 23 | +``` |
| 24 | + |
| 25 | +Once set, all Suga CLI commands will automatically authenticate using the token. |
| 26 | + |
| 27 | +## Prerequisites |
| 28 | + |
| 29 | +Before setting up CI/CD authentication, you need to: |
| 30 | + |
| 31 | +1. [Create a Personal Access Token](/guides/personal-access-tokens) |
| 32 | +2. Securely store the token in your CI/CD platform's secrets management system |
| 33 | + |
| 34 | +<Note> |
| 35 | +Never commit tokens directly to your repository. Always use your CI/CD platform's encrypted secrets or environment variable features. |
| 36 | +</Note> |
| 37 | + |
| 38 | +## Platform-Specific Setup |
| 39 | + |
| 40 | +<Tabs> |
| 41 | +<Tab title="GitHub Actions"> |
| 42 | + |
| 43 | +### GitHub Actions |
| 44 | + |
| 45 | +<Steps> |
| 46 | + <Step title="Add Token to Repository Secrets"> |
| 47 | + 1. Navigate to your GitHub repository |
| 48 | + 2. Go to **Settings** > **Secrets and variables** > **Actions** |
| 49 | + 3. Click **New repository secret** |
| 50 | + 4. Name: `SUGA_ACCESS_TOKEN` |
| 51 | + 5. Value: Your Personal Access Token |
| 52 | + 6. Click **Add secret** |
| 53 | + </Step> |
| 54 | + |
| 55 | + <Step title="Use in Workflow"> |
| 56 | + |
| 57 | + ```yaml |
| 58 | + name: Deploy with Suga |
| 59 | + |
| 60 | + on: |
| 61 | + push: |
| 62 | + branches: [main] |
| 63 | + |
| 64 | + jobs: |
| 65 | + deploy: |
| 66 | + runs-on: ubuntu-latest |
| 67 | + steps: |
| 68 | + - uses: actions/checkout@v4 |
| 69 | + |
| 70 | + - name: Install Suga CLI |
| 71 | + run: | |
| 72 | + curl -sSL https://addsuga.com/install | sh |
| 73 | + echo "$HOME/.suga/bin" >> $GITHUB_PATH |
| 74 | +
|
| 75 | + - name: Build and Deploy |
| 76 | + env: |
| 77 | + SUGA_ACCESS_TOKEN: ${{ secrets.SUGA_ACCESS_TOKEN }} |
| 78 | + run: | |
| 79 | + suga build |
| 80 | + # Additional deployment commands |
| 81 | + ``` |
| 82 | +
|
| 83 | + **Documentation**: [GitHub Actions Secrets](https://docs.github.com/en/actions/security-guides/encrypted-secrets) |
| 84 | + </Step> |
| 85 | +</Steps> |
| 86 | +
|
| 87 | +</Tab> |
| 88 | +
|
| 89 | +<Tab title="GitLab CI"> |
| 90 | +
|
| 91 | +### GitLab CI |
| 92 | +
|
| 93 | +<Steps> |
| 94 | + <Step title="Add Token to CI/CD Variables"> |
| 95 | + 1. Navigate to your GitLab project |
| 96 | + 2. Go to **Settings** > **CI/CD** > **Variables** |
| 97 | + 3. Click **Add variable** |
| 98 | + 4. Key: `SUGA_ACCESS_TOKEN` |
| 99 | + 5. Value: Your Personal Access Token |
| 100 | + 6. Check **Mask variable** and **Protect variable** (recommended) |
| 101 | + 7. Click **Add variable** |
| 102 | + </Step> |
| 103 | + |
| 104 | + <Step title="Use in Pipeline"> |
| 105 | + |
| 106 | + ```yaml |
| 107 | + stages: |
| 108 | + - build |
| 109 | + - deploy |
| 110 | +
|
| 111 | + variables: |
| 112 | + SUGA_VERSION: "latest" |
| 113 | +
|
| 114 | + before_script: |
| 115 | + - curl -sSL https://addsuga.com/install | sh |
| 116 | + - export PATH="$HOME/.suga/bin:$PATH" |
| 117 | +
|
| 118 | + build: |
| 119 | + stage: build |
| 120 | + script: |
| 121 | + - suga build |
| 122 | + only: |
| 123 | + - main |
| 124 | +
|
| 125 | + deploy: |
| 126 | + stage: deploy |
| 127 | + script: |
| 128 | + - suga build |
| 129 | + # Additional deployment commands |
| 130 | + only: |
| 131 | + - main |
| 132 | + ``` |
| 133 | + |
| 134 | + **Documentation**: [GitLab CI/CD Variables](https://docs.gitlab.com/ee/ci/variables/) |
| 135 | + </Step> |
| 136 | +</Steps> |
| 137 | + |
| 138 | +</Tab> |
| 139 | + |
| 140 | +<Tab title="CircleCI"> |
| 141 | + |
| 142 | +### CircleCI |
| 143 | + |
| 144 | +<Steps> |
| 145 | + <Step title="Add Token to Environment Variables"> |
| 146 | + 1. Navigate to your CircleCI project |
| 147 | + 2. Click **Project Settings** |
| 148 | + 3. Go to **Environment Variables** |
| 149 | + 4. Click **Add Environment Variable** |
| 150 | + 5. Name: `SUGA_ACCESS_TOKEN` |
| 151 | + 6. Value: Your Personal Access Token |
| 152 | + 7. Click **Add Variable** |
| 153 | + </Step> |
| 154 | + |
| 155 | + <Step title="Use in Config"> |
| 156 | + |
| 157 | + ```yaml |
| 158 | + version: 2.1 |
| 159 | +
|
| 160 | + jobs: |
| 161 | + build-and-deploy: |
| 162 | + docker: |
| 163 | + - image: cimg/base:stable |
| 164 | + steps: |
| 165 | + - checkout |
| 166 | +
|
| 167 | + - run: |
| 168 | + name: Install Suga CLI |
| 169 | + command: | |
| 170 | + curl -sSL https://addsuga.com/install | sh |
| 171 | + echo 'export PATH=$HOME/.suga/bin:$PATH' >> $BASH_ENV |
| 172 | +
|
| 173 | + - run: |
| 174 | + name: Build with Suga |
| 175 | + command: suga build |
| 176 | +
|
| 177 | + - run: |
| 178 | + name: Deploy |
| 179 | + command: | |
| 180 | + # Additional deployment commands |
| 181 | +
|
| 182 | + workflows: |
| 183 | + version: 2 |
| 184 | + build-deploy: |
| 185 | + jobs: |
| 186 | + - build-and-deploy: |
| 187 | + filters: |
| 188 | + branches: |
| 189 | + only: main |
| 190 | + ``` |
| 191 | + |
| 192 | + **Documentation**: [CircleCI Environment Variables](https://circleci.com/docs/env-vars/) |
| 193 | + </Step> |
| 194 | +</Steps> |
| 195 | + |
| 196 | +</Tab> |
| 197 | + |
| 198 | +<Tab title="Jenkins"> |
| 199 | + |
| 200 | +### Jenkins |
| 201 | + |
| 202 | +<Steps> |
| 203 | + <Step title="Add Token to Jenkins Credentials"> |
| 204 | + 1. Navigate to **Manage Jenkins** > **Manage Credentials** |
| 205 | + 2. Select the appropriate domain |
| 206 | + 3. Click **Add Credentials** |
| 207 | + 4. Kind: **Secret text** |
| 208 | + 5. Secret: Your Personal Access Token |
| 209 | + 6. ID: `suga-access-token` |
| 210 | + 7. Description: "Suga Personal Access Token" |
| 211 | + 8. Click **OK** |
| 212 | + </Step> |
| 213 | + |
| 214 | + <Step title="Use in Pipeline"> |
| 215 | + |
| 216 | + ```groovy |
| 217 | + pipeline { |
| 218 | + agent any |
| 219 | +
|
| 220 | + environment { |
| 221 | + SUGA_ACCESS_TOKEN = credentials('suga-access-token') |
| 222 | + } |
| 223 | +
|
| 224 | + stages { |
| 225 | + stage('Install Suga') { |
| 226 | + steps { |
| 227 | + sh ''' |
| 228 | + curl -sSL https://addsuga.com/install | sh |
| 229 | + export PATH=$HOME/.suga/bin:$PATH |
| 230 | + ''' |
| 231 | + } |
| 232 | + } |
| 233 | +
|
| 234 | + stage('Build') { |
| 235 | + steps { |
| 236 | + sh ''' |
| 237 | + export PATH=$HOME/.suga/bin:$PATH |
| 238 | + suga build |
| 239 | + ''' |
| 240 | + } |
| 241 | + } |
| 242 | +
|
| 243 | + stage('Deploy') { |
| 244 | + steps { |
| 245 | + sh ''' |
| 246 | + export PATH=$HOME/.suga/bin:$PATH |
| 247 | + # Additional deployment commands |
| 248 | + ''' |
| 249 | + } |
| 250 | + } |
| 251 | + } |
| 252 | + } |
| 253 | + ``` |
| 254 | + |
| 255 | + **Documentation**: [Jenkins Credentials](https://www.jenkins.io/doc/book/using/using-credentials/) |
| 256 | + </Step> |
| 257 | +</Steps> |
| 258 | + |
| 259 | +</Tab> |
| 260 | +</Tabs> |
| 261 | + |
| 262 | +## Using Tokens with Docker |
| 263 | + |
| 264 | +When running Suga CLI in Docker containers, pass the token as an environment variable: |
| 265 | + |
| 266 | +```dockerfile |
| 267 | +FROM ubuntu:22.04 |
| 268 | +
|
| 269 | +# Install Suga CLI |
| 270 | +RUN curl -sSL https://addsuga.com/install | sh |
| 271 | +
|
| 272 | +# Add Suga to PATH |
| 273 | +ENV PATH="$HOME/.suga/bin:${PATH}" |
| 274 | +
|
| 275 | +# Token will be provided at runtime |
| 276 | +ENV SUGA_ACCESS_TOKEN="" |
| 277 | +
|
| 278 | +WORKDIR /app |
| 279 | +COPY . . |
| 280 | +
|
| 281 | +CMD ["suga", "build"] |
| 282 | +``` |
| 283 | + |
| 284 | +Run the container: |
| 285 | + |
| 286 | +```bash |
| 287 | +docker run -e SUGA_ACCESS_TOKEN="your-token-here" your-image |
| 288 | +``` |
| 289 | + |
| 290 | +## Common CI/CD Workflows |
| 291 | + |
| 292 | +### Basic Build and Deploy |
| 293 | + |
| 294 | +```bash |
| 295 | +# Set token (typically done by CI platform) |
| 296 | +export SUGA_ACCESS_TOKEN="your-token-here" |
| 297 | +
|
| 298 | +# Build infrastructure |
| 299 | +suga build |
| 300 | +
|
| 301 | +# Deploy or additional commands |
| 302 | +# ... |
| 303 | +``` |
| 304 | + |
| 305 | +### Conditional Deployment |
| 306 | + |
| 307 | +```yaml |
| 308 | +# GitLab CI example |
| 309 | +deploy: |
| 310 | + stage: deploy |
| 311 | + script: |
| 312 | + - suga build |
| 313 | + only: |
| 314 | + - main |
| 315 | + - tags |
| 316 | + except: |
| 317 | + - schedules |
| 318 | +``` |
| 319 | + |
| 320 | +## Using Tokens with Suga API |
| 321 | + |
| 322 | +Personal Access Tokens can also be used directly with the Suga API as Bearer tokens: |
| 323 | + |
| 324 | +```bash |
| 325 | +curl -H "Authorization: Bearer your-token-here" \ |
| 326 | + https://app.addsuga.com/api/teams/{your_team}/platforms |
| 327 | +``` |
| 328 | + |
| 329 | +```javascript |
| 330 | +// Node.js example |
| 331 | +const response = await fetch('https://app.addsuga.com/api/teams/{your_team}/platforms', { |
| 332 | + headers: { |
| 333 | + 'Authorization': `Bearer ${process.env.SUGA_ACCESS_TOKEN}` |
| 334 | + } |
| 335 | +}); |
| 336 | +``` |
| 337 | + |
| 338 | +```python |
| 339 | +# Python example |
| 340 | +import os |
| 341 | +import requests |
| 342 | + |
| 343 | +headers = { |
| 344 | + 'Authorization': f'Bearer {os.environ["SUGA_ACCESS_TOKEN"]}' |
| 345 | +} |
| 346 | + |
| 347 | +response = requests.get('https://app.addsuga.com/api/teams/{your_team}/platforms', headers=headers) |
| 348 | +``` |
| 349 | + |
| 350 | +## Next Steps |
| 351 | + |
| 352 | +- [Personal Access Tokens Guide](/guides/personal-access-tokens) |
| 353 | +- [Suga CLI Reference](/cli) |
| 354 | +- [Environment Configuration](/cli/config) |
| 355 | +- [Build Command Reference](/cli/build) |
0 commit comments