Skip to content

Conversation

@lbussell
Copy link
Member

@lbussell lbussell commented Sep 3, 2025

Fixes https://github.com/dotnet/dotnet-docker-internal/issues/8828.

Important note: "unofficial" != "low privilege". That's why the template is still called secrets-unofficial instead of secrets-low.

  • Low privilege secrets are safe to reference from any pipeline, they shouldn't give any write access anywhere.
  • Unofficial secrets may give write access to non-production resources.

The reference to the DotNet-Docker-Secrets-Unofficial variable group was only removed because the unofficial pipelines don't currently use it for anything. We might add it back in the future to enable more functionality in unofficial pipelines.

@lbussell lbussell requested a review from a team as a code owner September 3, 2025 21:06
@lbussell lbussell merged commit 7841dec into dotnet:main Sep 5, 2025
20 checks passed
@lbussell lbussell deleted the secrets-low branch September 5, 2025 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants