Repository navigation
Use PSGALLERY_API_KEY for PowerShell Gallery publishing #343
Copy link
Copy link
Labels
MajordocumentationImprovements or additions to documentationImprovements or additions to documentationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions code
Description
Activity
- addedgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codedocumentationImprovements or additions to documentationImprovements or additions to documentation
on Jul 4, 2026 MariusStorhaug commented
on Jul 4, 2026 MemberAuthorMore actionsRestructured the issue description into the standard three-section format and grounded it in the current workflow source.
- Reframed Context and request as current vs. desired experience, and added the secondary finding that the secret is referenced with inconsistent casing (
APIKeydeclared,secrets.APIKEYinPublish-Module.yml,secrets.APIKeyinworkflow.ymland the two self-test workflows) — this works only because GitHub secret names are case-insensitive. - Made the breaking change explicit: renaming the declared secret changes the workflow's public
workflow_callsecrets contract, breaking both explicit-mapping consumers andsecrets: inheritconsumers. Added a warning callout and a consumer migration path. - Expanded Technical decisions: chosen name
PSGALLERY_API_KEY(with alternatives considered), scope boundary clarifying that thePSModule/Publish-PSModuleaction'sAPIKeyinput is not renamed (only thesecrets.*reference is), the hard-rename strategy vs. a deprecation-window alternative, casing standardization, and preservation of theWhatIfself-test wiring. - Rewrote the Implementation plan with concrete file paths:
workflow.yml,Publish-Module.yml,Workflow-Test-Default.yml,Workflow-Test-WithManifest.yml, andREADME.md(setup step, usage example, secrets table), plus rollout and verification steps. - Added labels
Major(breaking change),github_actions, anddocumentation. - Hyperlinked all external references (PowerShell Gallery, API keys page, PSModule org, reusable-workflow and secrets docs, the
Publish-PSModuleaction).
Note: an existing issue already covered this exact work, so it was restructured in place rather than opening a duplicate.
- Reframed Context and request as current vs. desired experience, and added the secondary finding that the secret is referenced with inconsistent casing (
MariusStorhaug commented
on Aug 9, 2026 MemberAuthorMore actionsRecorded implementation progress from PR #408.
- Completed the reusable-workflow secret rename and preserved the downstream
APIKeyaction input - Updated self-test callers, README, action documentation, and canonical workflow documentation
- Left organization secret rollout, end-to-end self-test runs, and real consumer publish verification open
- Completed the reusable-workflow secret rename and preserved the downstream
- changed the title
[-]Rename PSGallery API key secret from `APIKEY` to `PSGALLERY_API_KEY`[/-][+]Use PSGALLERY_API_KEY for PowerShell Gallery publishing[/+]on Aug 9, 2026 MariusStorhaug commented
on Aug 9, 2026 MemberAuthorMore actionsUpdated the credential contract to use one name at every GitHub Actions boundary.
- Renamed the Publish-PSModule action input and environment variable to
PSGALLERY_API_KEY - Updated the PowerShell variable to
$psGalleryApiKeywhile retaining the cmdlet's-ApiKeyparameter - Removed legacy credential and migration guidance from the tracker
- Renamed the Publish-PSModule action input and environment variable to
- added a commit that references this issue
on Aug 9, 2026
Metadata
Metadata
Assignees
Labels
MajordocumentationImprovements or additions to documentationImprovements or additions to documentationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions code
Module maintainers need one self-describing PowerShell Gallery publishing credential across the reusable workflow, publishing action, configuration, and documentation. A single name makes the credential easy to audit and prevents mismatched caller and action contracts.
Request
Desired experience
Publishing a module requires
PSGALLERY_API_KEYat every workflow and action boundary. A caller provides that one credential, and the reusable workflow forwards it unchanged to the publishing action.Acceptance criteria
PSGALLERY_API_KEYPSGALLERY_API_KEYPSGALLERY_API_KEYTechnical decisions
Credential contract: Use
PSGALLERY_API_KEYfor the workflow secret, publishing action input, and action environment variable. This name is explicit about both its service and purpose.PowerShell command interface: The underlying
Publish-PSResourcecmdlet keeps its-ApiKeyparameter because that is the cmdlet's public PowerShell interface. The value passed to it is held in the action's$psGalleryApiKeyvariable.Workflow scope: Publish-Module forwards
PSGALLERY_API_KEYdirectly to Publish-PSModule. No translation is needed at any GitHub Actions boundary.Documentation: Setup, caller, workflow-reference, design, and action documentation name only
PSGALLERY_API_KEYas the required publishing credential.Implementation plan
Credential contract
PSGALLERY_API_KEYin the root reusable workflow and Publish-Module workflowPSGALLERY_API_KEY$psGalleryApiKeyDocumentation and validation
PSGALLERY_API_KEYImplementation is delivered by PR #408.