Skip to content

Identity prompt should not overwrite existing GitHub secrets #121

Description

@petehauge

Problem

The identity prompt that sets up the GitHub ↔ Azure connection may overwrite existing GitHub repository secrets. For example, if a user already has a secret named AZURE_SUBSCRIPTION_ID for other workflows, the identity prompt will silently overwrite it, potentially breaking their existing CI/CD pipelines.

Proposed Solution

Update the identity prompt to check for existing secrets and interactively prompt the user before writing:

  1. Check if the secret already exists — before setting each secret (e.g., AZURE_SUBSCRIPTION_ID, AZURE_CLIENT_ID, AZURE_TENANT_ID), query the GitHub API to see if a secret with that name is already present
  2. If a conflict exists, prompt the user — show the user which secrets already exist and ask whether they want to:
    • Overwrite the existing secret (e.g., if it's from a previous APIOps setup)
    • Use a different name (e.g., APIOPS_AZURE_SUBSCRIPTION_ID) — let the user confirm or customize the alternative name
    • Reuse the existing secret — if the existing value is already correct, skip setting it
  3. Update pipeline references — ensure the scaffolded pipeline YAML files reference the correct secret names based on the user's choices
  4. Inform the user — summarize what was set and what was skipped/renamed

Acceptance Criteria

  • Identity prompt checks for existing GitHub secrets before creating new ones
  • If a conflict is detected, the user is prompted with options (overwrite, rename, or reuse)
  • User can choose or customize alternative secret names
  • Scaffolded pipeline files reference the correct secret names based on user choices
  • Existing secrets are never silently overwritten

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugSomething brokenP0Blocking releaseclose:fixedFixed by a previous PR or release

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions