Hi, the webhook from pact broker is getting trigge...
# pact-broker
h
Hi, the webhook from pact broker is getting triggered but is not executing the Jenkins Job and giving "Authentication required" error from Jenkins. I think to solve this, we might have to provide the username:password in Jenkins URL for authentication, however this seems to be an insecure way of accessing Jenkins as we are hardcoding the password in the URL (which gets reflected in webhook logs). Is there any other way of authenticating the webhook URL in Pact Broker?
g
Webhooks can have username and password parameters that get passed in when it makes the request (but the password isn’t shown if you GET the webook). There’s a Jenkins example in the docs. I don’t know if this is possible, but it would be nice to pass it through env variables instead so you could do
"password": "${env.JENKINS_PASS}"
and pass
JENKINS_PASS
to the Pact Broker container.
m
There is probably already a feature request for that. It was one of the first features we added to Pactflow (secrets handling) if that's an option for you
h
@Matt (pactflow.io / pact-js / pact-go) could you please share a document?
@Greg Tyler will pact broker trigger the webhook or do we have to trigger ourself by curl with template library code? If it is triggered internally by broker then what is the use of template library code?
g
The webhooks in the template library are examples of what you might tell Pact Broker to to verify a contract with a few different CI tools. They’re automatically triggered when you upload a new Pact (that’s different to the last changed one), so the process is: 1. Consumer runs tests, generates contract 2. Consumer publishes contract to Pact Broker 3. Pact Broker triggers whatever webhooks you’ve defined (like the ones in the template library) 4. Provider, triggered by that webhook, verifies that the contract is valid
👍 1
h
@Greg Tyler #3, how can we 'define' webhook? We only know about creating webhook with create-webhook command
g
I think the three options are that command, calling the API or Terraform (which is what I’m using)
👍 1
m
could you please share a document?
sorry, a document on what exactly?
h
A document on secrets handling
m
Oh, I was referring to PactFlow - e.g. https://pactflow.io/features/
The OSS Pact Broker does not manage secrets, with the only exception that it does try to obscure certain known authorization headers in the UI
They are stored as plain text in the DB and are visible in API calls / the HAL browser