Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

CI/CD: optional GITHUB_TOKEN for composer, functional tests never send email, registry secret apply (template !12)

Closed
#180 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
58/100
Issue type
Documentation
Clarity
Clearly specified
Activity status
Active
Tech stack
docker, github-actions, helm, kubernetes, php

Research direction

Update content/6.deployment/3.ci-cd.md, especially the variables table at line 73, the bin/devops/setup.sh section around line 147, and run_test_functional around line 167; compare with content/6.deployment/1.docker.md at line 224. Document the token, email-safe test setup, registry secret, Helm defaults, removed VARNISH_TOKEN, and stale GitHub deploy statement using the issue details. Done when the CI/CD guide consistently describes these behaviors and no longer lists the unused variable.

Written by the indexing model from the issue text.

Description

Template MR !12 (components-web-app#123, merged as 1a530d4) changed CI in ways content/6.deployment/3.ci-cd.md should cover.

1. Optional GITHUB_TOKEN for composer (new row in the variables table, plus a note in the bin/devops/setup.sh section, line 147)

  • Without it, composer's ~180 downloads from github.com are anonymous: 60 requests an hour per IP. On a shared runner, installs fail part way through with a 429.
  • A fine-grained token with no permissions is enough. setup.sh turns it into COMPOSER_AUTH and sets COMPOSER_MAX_PARALLEL_HTTP=6. Unset stays unset (an empty token is rejected outright, which is worse than anonymous).
  • build_api passes it to the API image build as the composer_auth build secret, never a build arg, so it stays out of the image history. The build log's github rate limit for this build: line prints 60 (anonymous) or 5000 (token applied).
  • GitHub Actions maps its own secrets.GITHUB_TOKEN on the build step, so nothing needs setting there.
  • Keep this consistent with content/6.deployment/1.docker.md:224, which already mentions GITHUB_TOKEN for local composer update.

2. Functional tests never send real email (the functional tests row at line 73, and run_test_functional at line 167)

  • Every CI variable reaches the test job, and a real environment variable beats api/.env.test, so a project's live MAILER_DSN would deliver any email a test sends (a contact form, a password reset).
  • run_test_functional unsets MAILER_DSN and MAILER_EMAIL, and api/.env.test sets MAILER_DSN=null://null: mail is built and Symfony's mailer assertions still see it, but nothing is delivered. Both halves are needed: without the .env.test line, tests fall back to .env's smtp-relay host, which CI doesn't have, and error.
  • The job also generates a test JWT keypair (lexik:jwt:generate-keypair --skip-if-exists), so tests that sign in work in CI.

3. Smaller changes

  • The registry pull secret is now kubectl applyd, not replace --forced (concurrent releases in one namespace raced with "already exists"). The first deploy after the change prints a harmless one-off warning about a missing last-applied-configuration annotation.
  • helm lint and helm template now pass on the chart's own defaults (jwt-passphrase defaults to "").
  • VARNISH_TOKEN (chart apiSecretToken) is gone: nothing read it. If the docs list it anywhere, remove it.

While there, unrelated: line 416 says "GitHub deploys don't pass these variables" (MAILER_DSN, MAILER_EMAIL, ORPHAN_SCAN*), but line 411 says they do. Since template #102 they do, so 416 looks stale.

Dominant language
Vue
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from components-web-app/docs

All issues in components-web-app/docs

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.