With the growing popularity of Infrastructure as Code (IaC) and cloud solutions, a resilient CI/CD pipeline is the foundation on which companies creating high-quality software rely. The GitLab continuous delivery system provides a flexible configuration interface that enables the use of the Twelve-Factor App methodology. The third rule says that anything that can vary between deployments must be stored in environment (environment) variables.

GitLab provides a clean user interface for defining environment variables. The values can be a short string or a JSON file. In addition, simple control flags allow you to define the availability and scope of variables (production/staging).

A special flag - masked variable - prevents secrets from leaking into the GitLab CI logs. However, restriction on the masked variable format forbids to obscure file env vars. It is an unacceptable vulnerability to store credentials as a plain text. Fortunately, programmatic configuration available from the composer shell command line is an elegant solution to this inconvenience.

Programmatically create auth.json

To create an entry in auth.json use composer config command. It works with an existing auth.json and can build it from scratch as well. Be sure to provide the full path, which is then expanded to JSON object notation. The following command composer config http-basic.repo.magento.com public-key private-key will create auth.json in the root directory:

{
  "http-basic": {
    "repo.magento.com": {
      username: "public-key",
      password: "private-key",
    },
  },
}

If the file already exists, a new entry will be added to the correct clause.

Another call to composer config http-basic.another.vendor.com other-public-key other-private-key will update http-basic with new line. Note that new record was added to the scope of existing http-basic key:

{
  "http-basic": {
    "repo.magento.com": {
      username: "public-key",
      password: "private-key",
    },
    "another.vendor.com": {
      username: "other-public-key",
      password: "other-private-key",
    },
  },
}

Script for creating composer auth.json

HTTP basic is one of the many authorization methods available for composer repositories. Let’s add gitlab-token to a Kustom Repo for demonstration. A simple template script that you can safely use in the GitLab CI can have the following contents:

#!/bin/bash
echo "Configuring composer auth.json..."
[[ -n $COMPOSER_MAGENTO_KEY ]] && composer config http-basic.repo.magento.com "$COMPOSER_MAGENTO_KEY" "$COMPOSER_MAGENTO_SECRET"
[[ -n $COMPOSER_GITLAB_KUSTOM_TOKEN ]] && composer config gitlab-token.gitlab.com "$COMPOSER_GITLAB_KUSTOM_TOKEN"

Empty or not configured environment variables are omitted.

Add exit 1 at the end of every line if you need to stop the pipeline when environment variable is missing

#!/bin/bash
# Breaks script if any command returns a non-zero exit status
set -e

echo "Configuring composer auth.json..."
[[ -n $COMPOSER_MAGENTO_KEY ]] && composer config http-basic.repo.magento.com "$COMPOSER_MAGENTO_KEY" "$COMPOSER_MAGENTO_SECRET" || exit 1
[[ -n $COMPOSER_GITLAB_KUSTOM_TOKEN ]] && composer config gitlab-token.gitlab.com "$COMPOSER_GITLAB_KUSTOM_TOKEN" || exit 1

You can ‘echo’ a missing variable name, this part was removed for brevity.

Refer to documentation for additional options on the composer website. Learn more about Twelve-Factor methodology.

Frequently asked questions

Composer auth.json in GitLab CI

How do I create auth.json with the composer command line?

Run `composer config http-basic.repo.magento.com public-key private-key` and Composer writes the credentials to auth.json in the project root. The command builds the file from scratch when it does not exist. When the file already exists, it adds the new entry under the existing http-basic key instead of overwriting it.

Why not store auth.json as a GitLab CI file variable?

GitLab masked variables keep secrets out of CI job logs, but the masked variable format restrictions do not allow masking file variables. A whole auth.json stored as a file variable leaves the credentials in plain text. Store each key as a separate masked variable and build auth.json with `composer config` during the job.

How do I add a GitLab token to Composer auth.json?

Run `composer config gitlab-token.gitlab.com "$COMPOSER_GITLAB_KUSTOM_TOKEN"`, where the variable holds the token defined in GitLab CI/CD settings. Composer adds a gitlab-token entry for gitlab.com to auth.json. The same script can also add http-basic credentials for repo.magento.com.

How do I fail a GitLab CI job when a Composer credential variable is missing?

Add `set -e` at the top of the script and append `|| exit 1` to each `composer config` line guarded by a `[[ -n $VARIABLE ]]` check. Without `|| exit 1`, empty or unset variables are skipped and the pipeline continues. With it, the script stops with a non-zero status as soon as a required variable is missing.

Share