From 2956adf264f5a115f398a8dbf87f37113f2587be Mon Sep 17 00:00:00 2001 From: Sarah Edwards Date: Mon, 1 Feb 2021 13:25:43 -0800 Subject: [PATCH 1/4] BYOK key is disabled, not deleted (#17512) --- ...figuring-data-encryption-for-your-enterprise.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/content/admin/configuration/configuring-data-encryption-for-your-enterprise.md b/content/admin/configuration/configuring-data-encryption-for-your-enterprise.md index 2d426fccb9..d6da59782a 100644 --- a/content/admin/configuration/configuring-data-encryption-for-your-enterprise.md +++ b/content/admin/configuration/configuring-data-encryption-for-your-enterprise.md @@ -20,7 +20,7 @@ For encryption in transit, {% data variables.product.product_name %} uses Transp The key that you provide is stored in a hardware security module (HSM) in a key vault that {% data variables.product.company_short %} manages. -To configure your encryption key, use the REST API. There are a number of API endpoints, for example to check the status of encryption, update your encryption key, and delete your encryption key. Note that deleting your key will freeze your enterprise. For more information about the API endpoints, see "[Encryption at rest](/rest/reference/enterprise-admin#encryption-at-rest)" in the REST API documentation. +To configure your encryption key, use the REST API. There are a number of API endpoints, for example to check the status of encryption, update your encryption key, and disable your encryption key. Note that disabling your key will freeze your enterprise. For more information about the API endpoints, see "[Encryption at rest](/rest/reference/enterprise-admin#encryption-at-rest)" in the REST API documentation. ### Adding or updating an encryption key @@ -48,24 +48,24 @@ Your 2048 bit RSA private key should be in PEM format, for example in a file cal curl -X GET http(s)://hostname/api/v3/enterprise/encryption/status/request_id ``` -### Deleting your encryption key +### Disabling your encryption key -To freeze your enterprise, for example in the case of a breach, you can disable encryption at rest by deleting your encryption key. +To freeze your enterprise, for example in the case of a breach, you can disable encryption at rest by marking your encryption key as disabled. -To unfreeze your enterprise after you've deleted your encryption key, contact support. For more information, see "[About {% data variables.contact.enterprise_support %}](/admin/enterprise-support/about-github-enterprise-support)." - -1. To delete your key and disable encryption at rest, use the `DELETE /enterprise/encryption` endpoint. +1. To disable your key and encryption at rest, use the `DELETE /enterprise/encryption` endpoint. This operation does not delete the key permanently. ```shell curl -X DELETE http(s)://hostname/api/v3/enterprise/encryption ``` -2. Optionally, check the status of the delete operation. +2. Optionally, check the status of the delete operation. It takes approximately ten minutes to disable encryption at rest. ```shell curl -X GET http(s)://hostname/api/v3/enterprise/encryption/status/request_id ``` +To unfreeze your enterprise after you've disabled your encryption key, contact support. For more information, see "[About {% data variables.contact.enterprise_support %}](/admin/enterprise-support/about-github-enterprise-support)." + ### Further reading - "[Encryption at rest](/rest/reference/enterprise-admin#encryption-at-rest)" in the REST API documentation From 021d5fffd4c1c7afef1c6a97166363c494987810 Mon Sep 17 00:00:00 2001 From: Ethan Palm <56270045+ethanpalm@users.noreply.github.com> Date: Mon, 1 Feb 2021 16:39:47 -0500 Subject: [PATCH 2/4] Update image (#17575) --- .../help/settings/token_description.png | Bin 4257 -> 7873 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/assets/images/help/settings/token_description.png b/assets/images/help/settings/token_description.png index e3eccd2846f10df2f3086ac13543bcbc7ba523d3..ca7a033763ef7c55f34907de6161f4f3835efa35 100644 GIT binary patch literal 7873 zcmaKR1z1!;_ctscAqXrg2r3-{%hH|FBAp`LT}v#rbc=vUOD-iKAT1%%N(<70bhCtX z?YD&Q`~Twk_PKZO?97RobI+XlowE@tO0ooau=!2-X0nQ!NcYLh$ zV^oK%wWOqqyrd+Rii@L#wVgQ{8dIF9kr7aymFc^&v60dDK9*;AE*@&(;cwK8{JOt= zr|SJSkkyfuoUEreOGY${q0x#4S8b`a6(13IdPQoM*e#5pNK-!eJh@(MSeMB;fTb>i zH~T^!q;zM<&z~RkC95zvAby^EZ@~U`>2!3vu5`S=42Wi(oey?Zad1kUH& zXZZM2Q)Fax4%F=$%N*=Gwe0M6LK?9;?{PfP7Wfk9xlL(t(z-GN0uB&JWF`+8**GI7 z`+52?61m-hL?ZR^xskjWZ2>RPYI=>ZULjhBQI^#**O9kSR77J&wQrLTQ7v@T zO^&+J&@kSGqG6++K-4Xj1^73LKA45^uZ?DKMJS;zDKC$Ds++o)n>#?P99@=cyR8&;LE@l>jYEm+{?5JNNG*+&zPJ&>thldB7 z2N#>8izS#tKtKS@&I#t^1feKE5KjkJV<^Z0LVF|RpByQ3h^dRUldH9(1J#vWV-rU= zR}mVTD@FhL+|1J)YW-hL4v^brp%w_f8Ub^#v4j638^tPo)hnoC4K=sZk+QZ&nFpmq zl$)1Z_?rIz8u_or8%|A#xr?NuJ&Ms)^uPAKW&WRo|0mr6e?<=v(R7I`_3nL&dP(n_$I_hm4oQ zTYv|(Nmh2M@Xsvn(V#=4v34?er$G(_!{LmnyvZASV(;xH4~VZm`vYt+ zxbIP;1F5bqJSHUJEvr8PCQ}x#_yW<*2oS}F{3rDP&sG8)>>jagWl@Gb7IPk2)!N{5 zP&BIq7S1c2*4t>@sUj5N2poN?JNU4Li`m0Uc2-3Z^%VDH^~Vf^M^Z#cxA`NfNe%gV?O^; z6o*3V$cHD(Fx=0p)zfROw!$2n(+c}D#r)nnFEAEee$DI2ku4MD_eL~MoR!Dj+6EYi z5~~aM;$bzY$4`Szo4E8B41ADaQKaK@n0!O1kR&x;$=;hRKyiV6QhZrjx;8gIpVQA} z<|MiP>*KF4$icZ}Uekwq`or039e6sm#*fh_psR7Wo_NQ)T0f(`CU!2?Ns7 zSWXGffn$!p!+DN66cTN-C#c>$5&?1*D7J+1u*|KckQ9%Vs9$vXoe@Nm{#9LIcta7T z^ki}lG3~8WZx;gmee!pCHmyv?_*lj7cfA|Ml*eYc8==J8hlS-C>f0k&$9cRtr{EL2ZI$M_BKrJuL z5f!7Xns8p}h(r$`l#!7!8ACK{CY{fmn7C^ilmrJg{aw~Pc={BvL&+_kE(SZtT-7BTKO>tD0|3SXeY zQro^h_8z$~W?HSC^k~T|jk8hvX4CS-msLh{CftrAcL>tB+wv5W4qorcUAw3_AR_Ra zEpA~+R&pZ#uTKh$)yZaZ`ETgn8WX(|pNbODe`M%pJ3ce6vk zZ2+NLM2HO~|Akv~&+5~Oqx+JI@$}zB0;(2V6>*Yt+Syy*pOFUKAN1H&U-)pt0Q`W4 z#oZzXP`dHk{|9?AjDNVd$^l!nt50?gddv-=o{O7IvQAs;Ww?zPa&(xBZWv1Ue#D6; zJmJiP_{-`R(+^tFKNQ0zCwm+~GA6kzPNMYimKr*STW9@zJ-vh2IvqX}Yq{mc3RKw@ zJTk=3ueAp0A2MG1pxiIab`}s~%`Tqr^ac8Z0mxVi745Fx6Qb~@l|ZMtL#|+1_RzFK zq=%EsO>Bwu57Os^dghA%&|@pyNE;QGma2OBl(bmnr#9YdMx{h(`4-528#0vN!1R6^ zH@(Qr-;vESw<-n}_Q{y{KM@CYUb3EJ9cB==zWH?Id~SnNKh|rtBTWC{HFIs0CKoSD z7O;NWgL=K^bH{p?G~ZxN4uzLb`}RszB&SgP^*fE%i zI?<)$Ad1gNmRN3Y-1j#ZN*=oteEmjdpU@9h<_qDOxwWSH282HNPQoyHzY=iD&Lp^S zNNGP%sXl@~I&NY3&(u|zf||~4GnGG8N0U=6f8_Sz6$-C>B$X%I^ZoOxdGTL}o3RFb z)#dydB4ixO6D%AxDlD0oLQ)ARYNnIev!kUkq{1Qz?aeYHxjr7gHAsoSGcpyG&#}$O zvt?(=N+dTH`=`(bbvnpzk*s*#_{)3<%3loFhj6Yr#notclM-UQ_;Da#72CdbAY{$Hti5w3~oS zYM1HDHlrKP|A;R@f{648uGT`Q25^)X*VofyMJi_>T_-N|_&*sSdwB7RE=N z6oZZ-7})o6AY+K`x6q{u_a^+OyZ{nLMTr;#UyX(m&xL%$pI_CrN0v4xAU3|pO#&4k zGqwtbk4ZF;{f$BS^fCKE9E`7zOZrcOZk()-7|H^e%$cx69SiJlpNJXj$jiww!A1{{ zC#&u43;%))@MYgV?Jx%U6eTG(JA~SLY1h@)uWQP5xl!;kqpw|hlKwiWdnhGt*?%c< zKulOGZ7aqvAZYx1ylhUrDje8r+V!^hP}MNHWyar^?CikGbz?|A;=Hv(f#9$Mk|7Ft zI9Y2Oqy>y#?Wo^j3YH!1z2=qq8 z=2+$a-`$pP;4q_$PQ{{&(N9y!+~(xZ+n#f{?oc&uFX0j&DI|f54^iik-WRV2TY~Nq z)kO)Kl*G!!PX%5^ zPnO`urD++~ytJnGQcGb}c3A95Bb|aFF*+hon3P=)CJ)F4%VNk$#$p62^V|ABFN~z^ zmM{4YNhBUFD5u@Co}M04c1mT*Gd~>2A+aP_iytX!MyxwK0XuZbefIL?z z9dEecWng?f?fU2m*(1)nD{yd!3+wKp_STR1t_wcJ0fheCSbjCRdPOj}Tf6Aau2!*j zaiki(LgDG&Qg_R=NKgx#^37(M!4IhOd)@W-g4}NsEh>>!+Gy6){G{uodA5=vlP2X5 zY;lqc(=Rb-P|}PTV>U1%P^6k?rc7kBCQ@EgUv3+!^FyK|rW<0atcSmez#Eodu>}Xq zdmpWpZALIM<*BwQm%C2j$;r9x{aOou6E0PH)TEJi9=lV)mf-@*fFmAsyY=p=M%#2N zuX@bl+E+lK46@~Rb-_f?-|TF^nvz#n zXbA6rx+Uy@UvS^j*1QJVPvutZU1rsZ49O{}f$l9N6 z5!(G6wNeyt+KJ6>fbLliq|1Kw@x*s?*>eHDSEU8t2GrTG5p^B!b=faryhQsrTxJ9Eg>VSdz1or@=WAh?vKfTm0=Ux;X)$$8ZHK&bi=p! z2LBkzaJt!!d@SQMbo^cS@p!GY= z*^z{C0t${7^lA~Zzq29Qdc#jeKIh|8o;=`noX+R;^4>?lHJS|jTA(e2^l0^r`{0eK-uMuq@~$02?~Bi-Dzbv)zz)GkSaHtUng8tah6zO?R- zHAjz{+%>7iOm+r0>fI6Hq8E3V!Ga#8N4ssk)}g`K`)k9tDXo1R_MNQsLt_0Yd4vl$ z=lCoEkz9TV=h9U7%R~ZfI1rXA3Ew3p-h&XwU(7eC8Njvkyg=vN9=zQNAk#Qc&*8Xm zr|$R9Ob@gj1%@U+q<=7}mJbP*RL_5jE-Nb=zcs4SEu0~8S9?xRec>tA9U8YHjTbtK z)oDfXA`60<+^reuQ*kYQ1TodJ+C#RFI`bogokD`l0F^hnM!TZ;uYoU1#;n_0)~gyl zjL~!Fnv4;M+ResHSSR={=`&>xi_x{>hbBtr1_!*9KSra=X#TSECAnG;e;xhQ4tc8} z+_BRWAyekYb&ug1*c_w30|>c>{6KfpR677IqCW zz%TG-h(P}GD^ANwKfV~!UzzgZp#w*1C`sDcW8TbxGM4q8x04C??C z5fVA>=hu*)s!Wj*;Kt-?7X{7TYyc`%5+X-rN4O=P@b+idIgolD;O1HN#O6kMEW33wd{q&)XRT_!zQC!TK#HQAzWV zQr;=AogLysN?{Y1^Yn(J^0RHUc>7&dYsAd1v7z1XCJ)MH(##!Ua1|d5x6SCi%H>PDLLqMiU>!Dzhbm``*PZZ{Ox1M^ zTCDx}F>JZpmD%v7p74>t!}xrpk%lE=-khRsGpNAv-Ew91vI!^^(wuZw^X*sLH5v@f?!oY6)z+{eX8G4=D+1n9b{_6zp9SwRE zR+Uv;VD~WYJzUifYe*Io*=r-FJ%};{Dol6$XPgFR zEk?G=^qT`t?j~h>94Q@}_iOMA37K{hioG%qO25h$s6GP2y>PRzijTTeFx=hU`C;?i zK2f9{ml(3Yz=)`%vf15uM!9%Fp0`hh0_H`f@ki-$$B%l5`TgdAkqO99?61`r?9C@QWvv<$V2;7TEDNt<9`Q4OI{&a zI^XQqe*YSrhkfsneX?l`+t!ZpGs7hwuucU4SaHywMq#+Wia)l$w*R`=v~ZdF9{C~9 z-ZG5x$%Sqa(b4_BvnHPkmkMT(DS?c7W= z3xV`31dtSNhx=+@>Si0{hn-iyJLk&BlM}3us=1r}-k%V&Hn71_`XC%62MXNTDr_P9 zRg3-N^r5=NUFb^39K6ePCUE6uqdF6nk7Fq2KEp3=Tj6`z2<+tIxf^j)$)cYjg1G` zq3vWNvPkOrZLxETEyBRX9ov!nH2E&+Jv}5QvW>Dx;y;CmJ?!>)MrEFi0`}*XNsP5g zKiDA&FP5UA=7Yh98_w}ge@CCZ+1U>Kls%8^;8 z3zDPXo?nN89UH*IyM@WX?Y-5{@!je|ki*73DFvTdc!)Ehb#s+tajZi&-~`_Tlq^PR zqg9q8r3vFeR&M*-uprdQqF^6N8($EIHG0m3(LISE-6--bRO)}*t#JS6%XGm9k@veD z%O5>@6p>ZX(!E@PB}V04!y3vfz+o=A-ra654a396Hv4g& zQNfr|QW;O;Zfjr%+ZMJ`**4uu);@!0QIzU8N5}>QbT^JaKIp?-x`-y{MLRq^{Cao*YC&=?Vx>3XmF2ga6Bi31(xO($4bT^>DtbYv$0^0SEw3*IV=F{#V#rZa-EwV_9033(DUSSNdnoWWiM>7F-U zK*We%jLB`A_>w3 zO$&dXwA?9|_PgO|C4EqOO5s77@*&}$qi*Z*Ht&&R?dmBTqzEA)?Y2s5nVPWh?~%*$ zaNp*c>G!0})D9C|z5}#y-GO%}T&9W&Pd|OmTW$4SLHGt)!dCi4%tl)`mm{UHnYEcL zOYctI;BNyOBTXFb&W9j9G|K@)|6qqaIV+8K7P(5#D--YIsz(;)4pq3BD<34+cod=V z)zBPNnJkjt@8n!?d3cKnL>Qx0Z$~T^tsQSJ+g9(~l0PF9K2@ft6kFqH5m+AY#-MXHZ z9k5!W;N^R#{tsM~^9LFHp5%U;<011MIV24xrP^Xi14bj0(Wmq=H!k#$s9aZE?3k~o z#%eC`&fogv$XH#qRPK^61>NP3W|J@x2Tr;+ZLmpCKbwHA$7*SX>VcPl7PFz&Rsyfx za#-S4y|s7YiHUjs3o!_9u1KlLM_*j@o=XQYP@4|si^lH!%+ap#UG<;8%Zh=cWuXL- zZfTvmYRVaU24sTkuM#)RjdO!TzY(htdN}@Sh`guAH+3Ac~@3WrEEa=Dl$i_m6Mv#0b zhj#A-J6}Kf*}cif`zKLo@>*r_>ieSQU(QzTTP5D*%~#4LI=--P*33*3nBv@CnS_-G z1$kyH+m%OO;mUX90hkX4bMK^W&|f2`<87jH!Qit$uLQMkyi^=eLz3k`+5eXIrtbER z9UadKc)9b%^#;FAp~|}UmR)f-rj}1eRpoH~j`aku%X0o(sG?m><$~NbZ2;X%e?V%m zm=9a}HKhIK4!Ex}HQ`KmQ^Er>h@&gEQi>)iT?a`cA#}XLtxf)S*R)i)s97+~5oRjf zlx54)(Xf8GyFZq{!B)YjS;X&z4dmU_KF5`2k!hcXxc}&l(O&(DDKD)gRr=g0@P7ej C*FGiy literal 4257 zcmV;S5MJ+zP)8oVcsy_Ff%h_g_)T-*)TIRGcz+RhIyISY){^2pM8qowC!4&&1^j# ztEM!XBelBq>(^0x`k$Kbvt^rlEaP>`ShkGUY#FcFvSqwx%a-w)E#tM+g>_ZG6g4=*+dW98M;NNM38Ja&DUS0Zczx~$meE8vqFuLcSdt$h6+AT)q zyYIexyWIv392ix;`ueLax7_lotFDSM#)X3i4-PW^>Z`9l_~3(2Kl@a}vRAKO$^(K$GY2?u!)oiVzy7D6eyXt8V1U@C@4ojgOgA(%q!x5f3m<>{aS&u< zW8-%NzQdPR1BLqV&O7gX^2sOBD<{Qm)TmLtd-ryTXko~ZA^YyT?;d;XF=WVKpC*4+ zybj%-UF9vuude&vd+)v5Zo3)aRQT+(&w}Ox3oNkUf(vf5%{GFBzz|4Xd+oJ`$17sK z^2#eAGe}^4*IP9>)Hs5^n!0WBI-n!_+k+222>Sc&x1SE|yz|Z`?dz|#n;70vL8N{076|iR5HnT~+G${fjb@r@ri(7R2r>Y- zM~@!DP|Usk4%=_G`DXGjzx=Ys0Y&wWQ7?vDWtCMN`nl(xyWxf#w%B5et+v_<-@pI< z`!misV`^~jx#t!%<65x3yA6_xap>w-hKDof^}|Y1%hNw){K4g%{Tk^@4w-O8-~BSYpu0b z@jBpdv(fA-o?Q+YDtkZ6>+s>j1FshMD7W{TXP$YUeDcY7YgA^LWfqu#6&!4Io0u}_ISb3f@(ZX40odrM&JK~jdkNJBzRzw%j4=A61{`tN4-n-m#%cTZa zUww5beDTE>7hZT_3<|8E1HLBPGtWFT*IaWw_Sj=uu#S8C?z``5Vf*d3KjxTYEY`6m zpm5wAd0@Tp!VBfuU3c9z-+c20WnyAyBm;Kv9sc^J{o-{nu{YXiBPUfnyNuT#0k05% z)js^-gLwPaTW|g8Pk+KymReA-6rvMw1R9@OI`QHG2OMBo1m)w7JMOZ}F6-B?AHGbH zZqIXi`ZR*V*1)UbfA}F}jN9bdZMWS9_c#@dpei+Z!U-qX;R#w`*AoA?zx@qxabBN3 zeV%^$>1n2!27pvghICcD=9+6#91L55KOYGvw3E(DYtGA3ZYDTZeSN)1Ms@yi9p;>K z&f;}|>2=p#_v)*!E}mV+YsK*@Y>oIe;q|Gfo)WI%xr8J%V@<>>xay2E&barUdx5}$ zYk=>(>rOG;8*jY9bL5DTc5hZ>26MLj5p|q%&N=+c`1O%TA8{0XDc?}vaMDR9VJYl* z-+lKjw%B6PpuPdLiprmV{`tOr`@)l*nQ+;XjsF%|WDzkaPn$m_DDbn-KeJK`tQ|M; zYxG3kAob%2*Z))%tzxV|N3pa(Q_FkA<^lZ0u^UXH{v0C;?fD5b~ zcXeB@?O>^Z=~j@v3} z$1T!@jGJz{DH=4i9KfY)L{TPQw}(6N#1lbQ9x*EyiE2C=w6eS5;4YOwSr8($g`3k) zKRxz0qEEH39pa2ly7D-*0|n+d=yUKZ@QH>6Emm-ZiY%i`;0yO|6xedPKfph#i+Q@b z4&9zzwhG`ip|+{r%C5B?3?g9`{p1NZ>4vB(-o|~Lv17-=XdpgDv9aj~PZ^%Yv5eV* z*W>7XVzv|;46_vIj~SBOn476UsgZQ()XCIm?MM6y+2U6*v^8B!96srYCWh1DtonFg zhr-!SdCT7)DE?n(ayb_~$E!hB^qJ5@qrh2bomKcdp8om&TT=~Q6H3Cy-+6LD$pQm%Tc2hkFL?ci*6Wsx0M{QyX4e+GAE>0A>Z&;~yLN<-n1{MvNXdVoX(~oN}tM z(-I8SH;Y+?0ZlvJGw7Qkqf5>8jg1YyyHZstr<`g^=H{lB zmey?9s?EmX)qSg>wXHT-``$lz^w|1RNlcq9Th-bB;ZFzypE}D_`Z~%ozGU) zcx}7S+G}9rzV~IkX3KcZ)`caZr)(Lo)ovbZqhaHuN(&+X71=cdZmi$f42B{wUoy>U6cm<1iD3lHbffFHDVhE3q(h7Lw zkw-iZnhIIUPnO59(z8~c`j1CgQ=td4saM3&TPM6t57v?qpdJ?sg)^O$K6h-E>6saU=HqqKBr)05dnx9;D{6sL45rS_I;jW8vh?j$_sPm#rIDhci+qe9rCn?eJ;)KW_ULBeY&SWzZ) zEJ^|%&Q36j4pUf3pov=CV3dDqbJ=B=rBt9lK$ez{PB=6Ljh^&rI#jdM@?wjX{V)83~C*hZxEyon`&84 ziYGz|M#(3ienM>K)KgELZo27AXTS%z1z^C{UwaKv`K?H- zJ(p1)FhYlMP=ZJ?$D)02JJvE|L#MXvMD$AcWbB_Dk!H~^fB8$$j8l$D7_o9-P$H&#Z3 zsgRLX(=6pS1KF_S-J>mg$ zm|_OnprqqE;+4W&sx^Ad=%`gZ5v(j4;mIwUoneLN#~ynu z)xnO1x7>1zMH%?0!ob8&Py7_0~xoO$P$JODx&gHSqmU2_Kgx_=B=0*mC^uAo^VNx_4@0t zCka?qh`Ne+#hT!l?hkMyWekhpWr2?WA^CL!xb)U!3k6vR4cfB}N-?npNr)!A#+F}2 z#93BL2F}unAay6ADIvSSJ!<{yU;pAMFi<7Q$O#OHEz`Y&S3a3vD~s2^{q=8HK^|BQ zLrC~yxPSlq-!UYh9QP1HF*w53ltDHTAc8Wm#z0yzqtH=e$>t_zEh{uDB0wy|E9tA~ z3Ec3J=Z_I(?E2xD*1J5_OMzoV%t6EQJ~an^@{^y~(FaCRHNDu#v!M23Ef=BeL60;&v((I5CQwt7| zF)if_F1WxR9Nz=F%s>9|4`)I2U2G8hE!wdHn3z;Z9Vk2glNk{0?gi*k3)+e&B8HBp z_yn?rF7%4kb%}%}WM$odpxZ213e8P|@vagvU3mzO7OdLHPaisM6JKhrY@!xx z6;CAK-tn45xjE@Zn`OjoiJ2A#wa~0wIGg$P$NBz%^;+DScsGz;1brbtUWIJ@zfn+Z zaH4fv!)-kKTr~I8B7`V9M{GTX;@6DVKn6?D6e?KwVx3J^X&Kk9Fs*xGDL)ZyPIULu zH4zvPl5cEi=nUfd`-J)Xulf7h8LwGRwMxEUn=SKewv5+o+4A$;*|K%e%cx6w85ytH zsvEDw36mZXehqyWDO+`N@r(a+;cc&nTyyrlQ}A%PFU+>i0Nv%ISXqyvn{JDl@1500000NkvXXu0mjf D>BVVe From c640f6da161345f4da19f1ea367ad774810e6f6f Mon Sep 17 00:00:00 2001 From: Kevin Heis Date: Mon, 1 Feb 2021 14:25:49 -0800 Subject: [PATCH 3/4] Update Dockerfile so it builds and runs (#17469) * Update Dockerfile so it at least builds * And get it running again! * Update Dockerfile * Create build-docker-image.yml * Update build-docker-image.yml * Update Dockerfile * Update Dockerfile * Delete build-docker-image.yml --- .github/workflows/build-docker-image.yml | 23 +++++++++++++++++++++++ Dockerfile | 15 +++++++++++++-- 2 files changed, 36 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/build-docker-image.yml diff --git a/.github/workflows/build-docker-image.yml b/.github/workflows/build-docker-image.yml new file mode 100644 index 0000000000..7d0a44c3e7 --- /dev/null +++ b/.github/workflows/build-docker-image.yml @@ -0,0 +1,23 @@ +# Make sure the Docker container still builds + +name: Build Docker image + +on: + push: + branches: + - main + pull_request: + branches-ignore: + - translations + +env: + CI: true + +jobs: + build: + runs-on: ubuntu-latest + steps: + - name: Check out repo + uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f + - name: Build the container + run: docker build . diff --git a/Dockerfile b/Dockerfile index 59846b78f6..6e5205f763 100644 --- a/Dockerfile +++ b/Dockerfile @@ -7,18 +7,21 @@ # A temporary image that installs production-only dependencies FROM node:14-alpine as installation +RUN apk add --no-cache python make g++ ENV NODE_ENV production WORKDIR /usr/src/docs COPY package*.json ./ # Install the project's dependencies -RUN npm ci +RUN npm ci --production # -------------------------------------------------------------------------------- # BUNDLE IMAGE # A temporary image that installs dependencies and builds the production-ready front-end bundles. FROM node:14-alpine as bundles +RUN apk add --no-cache python make g++ +ENV NODE_ENV production WORKDIR /usr/src/docs # Install the files used to create the bundles COPY package*.json ./ @@ -27,7 +30,8 @@ COPY stylesheets ./stylesheets COPY lib ./lib COPY webpack.config.js ./webpack.config.js # Install the project's dependencies and build the bundles -RUN npm ci && npm run build +RUN npm ci --production +RUN npm run build # -------------------------------------------------------------------------------- # MAIN IMAGE @@ -52,16 +56,23 @@ COPY --chown=node:node --from=bundles /usr/src/docs/dist /usr/src/docs/dist # We should always be running in production mode ENV NODE_ENV production +# Use Lunr instead of Algolia +ENV USE_LUNR true + # Copy only what's needed to run the server COPY --chown=node:node assets ./assets COPY --chown=node:node content ./content COPY --chown=node:node data ./data COPY --chown=node:node includes ./includes +COPY --chown=node:node layouts ./layouts COPY --chown=node:node lib ./lib COPY --chown=node:node middleware ./middleware COPY --chown=node:node translations ./translations COPY --chown=node:node server.js ./server.js COPY --chown=node:node package*.json ./ +COPY --chown=node:node feature-flags.json ./ +EXPOSE 80 EXPOSE 443 +EXPOSE 4000 CMD ["node", "server.js"] From 8a3d415da423eb7a854c9fb1563ba56a0064915a Mon Sep 17 00:00:00 2001 From: github-openapi-bot <69533958+github-openapi-bot@users.noreply.github.com> Date: Mon, 1 Feb 2021 17:58:13 -0500 Subject: [PATCH 4/4] Update OpenAPI Descriptions (#17609) * Update OpenAPI Descriptions * Add decorated OpenAPI schema files Co-authored-by: Sarah Edwards --- lib/rest/static/decorated/github.ae.json | 4 ++-- lib/rest/static/dereferenced/github.ae.deref.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/lib/rest/static/decorated/github.ae.json b/lib/rest/static/decorated/github.ae.json index 9f9de893ea..7c466a825b 100644 --- a/lib/rest/static/decorated/github.ae.json +++ b/lib/rest/static/decorated/github.ae.json @@ -6153,7 +6153,7 @@ } ], "summary": "Disable encryption at rest", - "description": "**Warning:** The encryption at rest endpoints are currently in beta and are subject to change.\n\nDisables encryption at rest and deletes the encryption key. To freeze your enterprise, you can disable encryption at rest. For example, you can freeze your enterprise in the case of a breach. It takes approximately ten minutes to disable encryption at rest. To check the status, use the \"[Get an encryption status](https://docs.github.com/github-ae@latest/rest/reference/enterprise-admin#get-an-encryption-status)\" REST API.\n\nTo unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"[Receiving enterprise support](/admin/enterprise-support/receiving-help-from-github-support).\"", + "description": "**Warning:** The encryption at rest endpoints are currently in beta and are subject to change.\n\nMarks your encryption key as disabled and disables encryption at rest. This will freeze your enterprise. For example, you can use this operation to freeze your enterprise in case of a breach. Note: This operation does not delete the key permanently.\n\nIt takes approximately ten minutes to disable encryption at rest. To check the status, use the \"[Get an encryption status](https://docs.github.com/github-ae@latest/rest/reference/enterprise-admin#get-an-encryption-status)\" REST API.\n\nTo unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"[Receiving enterprise support](/admin/enterprise-support/receiving-help-from-github-support).\"", "operationId": "enterprise-admin/disable-encryption", "tags": [ "enterprise-admin" @@ -6176,7 +6176,7 @@ "subcategoryLabel": "Encryption at rest", "notes": [], "bodyParameters": [], - "descriptionHTML": "

Warning: The encryption at rest endpoints are currently in beta and are subject to change.

\n

Disables encryption at rest and deletes the encryption key. To freeze your enterprise, you can disable encryption at rest. For example, you can freeze your enterprise in the case of a breach. It takes approximately ten minutes to disable encryption at rest. To check the status, use the \"Get an encryption status\" REST API.

\n

To unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"Receiving enterprise support.\"

", + "descriptionHTML": "

Warning: The encryption at rest endpoints are currently in beta and are subject to change.

\n

Marks your encryption key as disabled and disables encryption at rest. This will freeze your enterprise. For example, you can use this operation to freeze your enterprise in case of a breach. Note: This operation does not delete the key permanently.

\n

It takes approximately ten minutes to disable encryption at rest. To check the status, use the \"Get an encryption status\" REST API.

\n

To unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"Receiving enterprise support.\"

", "responses": [ { "httpStatusCode": "202", diff --git a/lib/rest/static/dereferenced/github.ae.deref.json b/lib/rest/static/dereferenced/github.ae.deref.json index c2b211472b..88191914e8 100644 --- a/lib/rest/static/dereferenced/github.ae.deref.json +++ b/lib/rest/static/dereferenced/github.ae.deref.json @@ -12328,7 +12328,7 @@ }, "delete": { "summary": "Disable encryption at rest", - "description": "**Warning:** The encryption at rest endpoints are currently in beta and are subject to change.\n\nDisables encryption at rest and deletes the encryption key. To freeze your enterprise, you can disable encryption at rest. For example, you can freeze your enterprise in the case of a breach. It takes approximately ten minutes to disable encryption at rest. To check the status, use the \"[Get an encryption status](https://docs.github.com/github-ae@latest/rest/reference/enterprise-admin#get-an-encryption-status)\" REST API.\n\nTo unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"[Receiving enterprise support](/admin/enterprise-support/receiving-help-from-github-support).\"", + "description": "**Warning:** The encryption at rest endpoints are currently in beta and are subject to change.\n\nMarks your encryption key as disabled and disables encryption at rest. This will freeze your enterprise. For example, you can use this operation to freeze your enterprise in case of a breach. Note: This operation does not delete the key permanently.\n\nIt takes approximately ten minutes to disable encryption at rest. To check the status, use the \"[Get an encryption status](https://docs.github.com/github-ae@latest/rest/reference/enterprise-admin#get-an-encryption-status)\" REST API.\n\nTo unfreeze your enterprise after you've disabled encryption at rest, you must contact Support. For more information, see \"[Receiving enterprise support](/admin/enterprise-support/receiving-help-from-github-support).\"", "operationId": "enterprise-admin/disable-encryption", "tags": [ "enterprise-admin"