Warning
Unsupported software. This action is provided as is, without support. It may change or be withdrawn at any time. Issues and pull requests may not get a response.
A GitHub Action that forwards the event that triggered a workflow to a Terrateam server as a signed GitHub webhook. Use it when GitHub cannot deliver webhooks to your Terrateam server directly.
The action reads the event payload that GitHub gives the workflow, converts it
to the webhook that Terrateam decodes, signs it with your webhook secret
(X-Hub-Signature-256) and POSTs it to <terrateam-url>/api/github/v1/events.
name: Terrateam Webhook Proxy
on:
pull_request_target:
types: [opened, synchronize, reopened, ready_for_review, closed, edited]
issue_comment:
types: [created]
push:
permissions: {}
jobs:
forward:
runs-on: ubuntu-latest
steps:
- uses: stategraph/action-webhook-proxy@v1.0.0
with:
terrateam-url: https://terrateam.example.com
webhook-secret: ${{ secrets.TERRATEAM_WEBHOOK_SECRET }}
installation-id: ${{ vars.TERRATEAM_INSTALLATION_ID }}| Input | Required | Default | Description |
|---|---|---|---|
terrateam-url |
no | https://app.terrateam.io |
Base URL of the Terrateam server. |
webhook-secret |
yes | Secret used to sign the webhook. Must equal the server's GITHUB_WEBHOOK_SECRET. |
|
installation-id |
yes | ID of the Terrateam GitHub App installation for this repository. |
| Workflow event | Sent as |
|---|---|
pull_request |
pull_request |
pull_request_target |
pull_request |
issue_comment |
issue_comment |
push |
push |
For any other event, the action writes a notice and does nothing. Terrateam
defines no webhook for the pull_request activity types enqueued, dequeued
and demilestoned, so the action writes a notice for them too.
Use pull_request_target instead of pull_request if pull requests come from
forks: GitHub does not give secrets to pull_request workflows from forks.
pull_request_target is safe here because the action does not check out or run
code from the pull request.
GitHub documents the workflow's event payload as identical to the webhook payload of the event. The action converts it, event by event, to the webhook that Terrateam decodes, which holds only the members Terrateam reads:
| Webhook | Members sent |
|---|---|
| every event | repository (id, name, default_branch, owner.login, owner.type), sender (login, type), installation (from the installation-id input) |
pull_request |
action, number, pull_request.number; for edited, changes.base |
issue_comment |
action, comment.id, comment.body, issue.number, issue.pull_request |
push |
ref, after |
If the event payload does not have a member that the webhook requires, the step
fails and names the member, for example $.pull_request.number: missing. The
action does not invent values.
- A Linux or macOS runner with
python3(3.9 or later) on thePATH. The action uses only the Python standard library and does not use Docker or Node. - The action does not install its own crypto library. Signing (
hmac) and TLS (ssl) use the OpenSSL that the runner's Python is linked to, so the host's crypto policy applies. On a FIPS host, use a webhook secret of at least 14 bytes (112 bits), the minimum HMAC key length for FIPS-approved use; a FIPS provider can refuse a shorter key. - TLS uses the host's trust store. To trust a private CA, add it to the host
trust store or set
SSL_CERT_FILEin the step environment.
Releases are cut from main and tagged vX.Y.Z. A tag freezes everything the
action runs, so a tag is what you should pin to.
| Pin | Behaviour | Dependabot |
|---|---|---|
stategraph/action-webhook-proxy@v1.0.0 |
Frozen at one release. Recommended. | Pull requests for v1.0.1, v1.1.0, and so on. |
stategraph/action-webhook-proxy@<commit sha> # v1.0.0 |
Frozen at one commit. | Pull requests that advance the SHA and update the comment. |
There is no moving major tag. Pin to a release and let Dependabot raise the pull request. Pin to a commit that a release tag points at: for a SHA that carries no tag, Dependabot advances the pin to the head of the branch rather than to a release.
X changes only on a deliberate, announced break. Y increases when a release
adds functionality. Z increases for fixes and internal changes. Prereleases
are tagged v1.1.0-rc.1 and are marked as prereleases. See the Releases page
for the changelog.
Run the release workflow from the Actions tab. It always releases the head of
main:
release_kind:patch,minorormajorbumps the highest stable tag;specificusessemver_tagexactly (required for the first release).dry_run: computes the version and publishes nothing.
The workflow tags the commit and creates a GitHub Release with generated notes. It writes nothing into the tree.
$ PYTHONPATH=src python3 -m unittest discover -s tests -v
$ pip install mypy==1.20.2 && mypysrc/terrat_webhook_types.pyi is generated from Terrateam's webhook schema. Do
not edit it by hand. src/convert.py builds each webhook from these types, so
mypy fails when the schema changes and a conversion does not follow it.