feat(scaffolder-backend): add defaultEnvironment config to scaffolder
Signed-off-by: Rogerio Angeliski <angeliski@hotmail.com>
This commit is contained in:
@@ -64,6 +64,67 @@ you will not have any templates available to use. These need to be [added to the
|
||||
To get up and running and try out some templates quickly, you can or copy the
|
||||
catalog locations from the [create-app template](https://github.com/backstage/backstage/blob/master/packages/create-app/templates/default-app/app-config.yaml.hbs).
|
||||
|
||||
## Configuration
|
||||
|
||||
### Default Environment
|
||||
|
||||
The scaffolder supports a `defaultEnvironment` configuration that provides default parameters and secrets to all templates. This reduces template complexity and improves security by centralizing common values.
|
||||
|
||||
```yaml
|
||||
scaffolder:
|
||||
defaultEnvironment:
|
||||
parameters:
|
||||
region: eu-west-1
|
||||
organizationName: acme-corp
|
||||
defaultRegistry: registry.acme-corp.com
|
||||
secrets:
|
||||
AWS_ACCESS_KEY: ${AWS_ACCESS_KEY}
|
||||
GITHUB_TOKEN: ${GITHUB_TOKEN}
|
||||
DOCKER_REGISTRY_TOKEN: ${DOCKER_REGISTRY_TOKEN}
|
||||
```
|
||||
|
||||
#### Default parameters
|
||||
|
||||
Default parameters are accessible via `${{ environment.parameters.* }}` in templates. Default parameters are isolated in their own context to avoid naming conflicts.
|
||||
|
||||
```yaml
|
||||
parameters:
|
||||
- title: Fill in some steps
|
||||
required:
|
||||
- organizationName
|
||||
properties:
|
||||
organizationName:
|
||||
title: organizationName
|
||||
type: string
|
||||
description: Unique name of the organization
|
||||
ui:autofocus: true
|
||||
ui:options:
|
||||
rows: 5
|
||||
|
||||
steps:
|
||||
- id: deploy
|
||||
name: Deploy Application
|
||||
action: aws:deploy
|
||||
input:
|
||||
region: ${{ environment.parameters.region }} # Resolves to defaultEnvironment.parameters.region
|
||||
organization: ${{ parameters.organizationName }} # Resolves to frontend input value
|
||||
otherOrganization: ${{ environment.parameters.organizationName }} # Resolves to defaultEnvironment.parameters.organizationName
|
||||
```
|
||||
|
||||
#### Secrets
|
||||
|
||||
Default secrets are resolved from environment variables and accessible via `${{ environment.secrets.* }}` in template actions. Secrets are only available during action execution, not in frontend forms.
|
||||
|
||||
```yaml
|
||||
- id: deploy
|
||||
name: Deploy with credentials
|
||||
action: aws:deploy
|
||||
input:
|
||||
accessKey: ${{ environment.secrets.AWS_ACCESS_KEY }} # Resolves to defaultEnvironment.secrets.AWS_ACCESS_KEY
|
||||
```
|
||||
|
||||
**Security Note:** Secrets are automatically masked in logs and are only available to backend actions, never exposed to the frontend.
|
||||
|
||||
## Audit Events
|
||||
|
||||
The Scaffolder backend emits audit events for various operations. Events are grouped logically by `eventId`, with `subEventId` providing further distinction when needed.
|
||||
|
||||
Reference in New Issue
Block a user