`dependency add` and `project build` do not support Git HTTPS authentication for private dependencies
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 68/100
Research direction
Start with the dependency add and project build command entry points, then compare their dependency access with dependency update-cache, which already exposes the Git HTTPS credential options. Verify both commands read CROSSPLANE_GIT_TOKEN and CROSSPLANE_GIT_USERNAME, support the documented workflow, and keep credentials out of project files, URLs, logs, and errors.
Written by the indexing model from the issue text.
Description
What happened?
Our corporate network cannot access public source-code hosts such as GitHub. We mirror the CRD manifests we need in a private repository on our internal Git server and use that repository as a project dependency.
The CLI cannot authenticate to that repository when it is accessed by crossplane dependency add or crossplane project build.
This leaves us unable to:
- Add the Git dependency to a project in the first place.
- Build a project when its dependency schemas need to be generated or refreshed.
This is surprising because crossplane dependency update-cache already supports Git-over-HTTPS authentication with:
--git-token/CROSSPLANE_GIT_TOKEN--git-username/CROSSPLANE_GIT_USERNAME
The equivalent options are not available to dependency add or project build.
How can we reproduce it?
dependency add rejects the authentication flag:
$ crossplane dependency add --git-token=not-a-real-token
crossplane: error: unknown flag --git-token
The same flag is available on dependency update-cache:
$ crossplane dependency update-cache --help
...
--git-token=STRING Token for git HTTPS authentication ($CROSSPLANE_GIT_TOKEN).
--git-username="x-access-token"
Username for git HTTPS authentication ($CROSSPLANE_GIT_USERNAME).
I expect this workflow to work:
export CROSSPLANE_GIT_TOKEN=<read-only-token>
crossplane dependency add \
https://<git-server>/<organization>/<repository>.git \
--git-ref main \
--git-path config/crd/bases
After the dependency has been added, a regular build should also be able to access it:
crossplane project build
Both commands should use credentials supplied through environment variables. Credentials must not be written to crossplane-project.yaml, included in the repository URL, or exposed in logs and error messages.
I would be happy to contribute a fix for this issue.
What environment did it happen in?
- Crossplane CLI version:
v2.5.0 - Platform:
linux/amd64 - Crossplane version: not applicable
- Dominant language
- Go
- Stars
- 19
- Forks
- 33
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 52
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from crossplane/cli
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
crossplane/cli#282 ·
Maintainers usually reply within 2 days
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 58/100
crossplane/cli#394 · 1 comment ·
Maintainers usually reply within 2 days
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 68/100
crossplane/cli#392 · 1 comment ·
Maintainers usually reply within 2 days
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
crossplane/cli#391 ·
Maintainers usually reply within 2 days
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
crossplane/cli#386 · 1 reaction ·
Maintainers usually reply within 2 days
Similar issues
-
agent-butler-finding chore
Difficulty 1/5 Under an hour Newbie friendliness 88/100
jordansmall/spindrift#4146 ·
Maintainers usually reply within 1 day
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
IBM/ibmcloud-volume-file-vpc#119 ·
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
IBM/networking-go-sdk#339 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
kubernetes-sigs/mcp-lifecycle-operator#439 ·
Maintainers usually reply within 1 day
-
area: global bug dx priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day