Skip to content

Use PSGALLERY_API_KEY for PowerShell Gallery publishing #343

Description

Module maintainers need one self-describing PowerShell Gallery publishing credential across the reusable workflow, publishing action, configuration, and documentation. A single name makes the credential easy to audit and prevents mismatched caller and action contracts.

Request

Desired experience

Publishing a module requires PSGALLERY_API_KEY at every workflow and action boundary. A caller provides that one credential, and the reusable workflow forwards it unchanged to the publishing action.

Acceptance criteria

  • The reusable workflow declares and consumes PSGALLERY_API_KEY
  • The Publish-Module reusable workflow and Publish-PSModule action input use PSGALLERY_API_KEY
  • The publishing action's environment variable and PowerShell variable identify the PowerShell Gallery credential consistently
  • Canonical caller templates and Process-PSModule documentation require PSGALLERY_API_KEY
  • Publishing to the PowerShell Gallery continues to use the supplied credential

Technical decisions

Credential contract: Use PSGALLERY_API_KEY for the workflow secret, publishing action input, and action environment variable. This name is explicit about both its service and purpose.

PowerShell command interface: The underlying Publish-PSResource cmdlet keeps its -ApiKey parameter because that is the cmdlet's public PowerShell interface. The value passed to it is held in the action's $psGalleryApiKey variable.

Workflow scope: Publish-Module forwards PSGALLERY_API_KEY directly to Publish-PSModule. No translation is needed at any GitHub Actions boundary.

Documentation: Setup, caller, workflow-reference, design, and action documentation name only PSGALLERY_API_KEY as the required publishing credential.


Implementation plan

Credential contract

  • Declare and forward PSGALLERY_API_KEY in the root reusable workflow and Publish-Module workflow
  • Rename the Publish-PSModule action input and environment variable to PSGALLERY_API_KEY
  • Update the publishing script to use $psGalleryApiKey

Documentation and validation

  • Update canonical caller templates and Process-PSModule documentation
  • Run workflow self-tests and action unit tests
  • Confirm a real consumer publish to the PowerShell Gallery succeeds with PSGALLERY_API_KEY

Implementation is delivered by PR #408.

Activity

  1. MariusStorhaug commented on Jul 4, 2026

    @MariusStorhaug
    MemberAuthor

    Restructured the issue description into the standard three-section format and grounded it in the current workflow source.

    • Reframed Context and request as current vs. desired experience, and added the secondary finding that the secret is referenced with inconsistent casing (APIKey declared, secrets.APIKEY in Publish-Module.yml, secrets.APIKey in workflow.yml and the two self-test workflows) — this works only because GitHub secret names are case-insensitive.
    • Made the breaking change explicit: renaming the declared secret changes the workflow's public workflow_call secrets contract, breaking both explicit-mapping consumers and secrets: inherit consumers. Added a warning callout and a consumer migration path.
    • Expanded Technical decisions: chosen name PSGALLERY_API_KEY (with alternatives considered), scope boundary clarifying that the PSModule/Publish-PSModule action's APIKey input is not renamed (only the secrets.* reference is), the hard-rename strategy vs. a deprecation-window alternative, casing standardization, and preservation of the WhatIf self-test wiring.
    • Rewrote the Implementation plan with concrete file paths: workflow.yml, Publish-Module.yml, Workflow-Test-Default.yml, Workflow-Test-WithManifest.yml, and README.md (setup step, usage example, secrets table), plus rollout and verification steps.
    • Added labels Major (breaking change), github_actions, and documentation.
    • Hyperlinked all external references (PowerShell Gallery, API keys page, PSModule org, reusable-workflow and secrets docs, the Publish-PSModule action).

    Note: an existing issue already covered this exact work, so it was restructured in place rather than opening a duplicate.

  2. MariusStorhaug commented on Aug 9, 2026

    @MariusStorhaug
    MemberAuthor

    Recorded implementation progress from PR #408.

    • Completed the reusable-workflow secret rename and preserved the downstream APIKey action input
    • Updated self-test callers, README, action documentation, and canonical workflow documentation
    • Left organization secret rollout, end-to-end self-test runs, and real consumer publish verification open
  3. changed the title [-]Rename PSGallery API key secret from `APIKEY` to `PSGALLERY_API_KEY`[/-] [+]Use PSGALLERY_API_KEY for PowerShell Gallery publishing[/+] on Aug 9, 2026
  4. MariusStorhaug commented on Aug 9, 2026

    @MariusStorhaug
    MemberAuthor

    Updated the credential contract to use one name at every GitHub Actions boundary.

    • Renamed the Publish-PSModule action input and environment variable to PSGALLERY_API_KEY
    • Updated the PowerShell variable to $psGalleryApiKey while retaining the cmdlet's -ApiKey parameter
    • Removed legacy credential and migration guidance from the tracker
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    MajordocumentationImprovements or additions to documentationgithub_actionsPull requests that update GitHub Actions code

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions