Getting started
Connect to GitHub
Create the GitHub personal access token the installer asks for, and know exactly what the platform does with it.
Create a GitHub personal access token with the scopes listed below and paste it into the installer. It logs gh in for you, lets you publish templates, reads your own template metadata, and keeps a backup of your certificate.
Your code and your deployments live in Thinkube Git, inside the cluster. GitHub is used for four things that sit outside it:
-
Thinkube IDE logs the
ghcommand-line tool in with the token, soghworks from a terminal without a browser. -
When you publish an application as a template, Thinkube Control creates the repository in the GitHub account that owns the token and pushes the code there.
-
If you keep a repository named
<your username>-metadatathat lists your own templates, the installer reads it. It clones the templates marked for development into Thinkube IDE. -
The installer keeps an encrypted backup of your wildcard certificate in a private repository named
thinkube-certificatesunder the same account.
Container images are stored in Thinkube Registry, not on GitHub.
1. Create the token
-
Sign in to GitHub. Open your profile photo → Settings → Developer settings → Personal access tokens → Tokens (classic).
-
Choose Generate new token (classic).
-
Name it, for example
Thinkube. -
Set an expiry. The token is used after the install too, so choose one you will remember to renew.
-
Select these scopes. The installer checks for each of them and refuses a token that lacks one:
Scope Why repoCreate and push the repositories above
workflowPush repositories that contain GitHub Actions workflows
write:packagesThe installer requires it.
admin:packagesalso satisfies it.write:discussionThe installer requires it.
-
Generate token and copy it now. Classic tokens start with
ghp_.
2. Give it to the installer
The Configuration screen has one field, GitHub Personal Access Token. The installer calls GitHub with the token, reads the scopes GitHub reports for it, and shows a green mark when every required scope is present. A missing scope is named in the message.
Where it goes
-
~/.envon the machine running the installer, asGITHUB_TOKEN. The GitHub username is learned from the token, and kept asGITHUB_USERNAMEbeside it on the control plane. -
~/.envon the control plane. The installer copies it there, so later operations do not need the machine you installed from. -
Thinkube Control receives it as a secret when it is deployed; that is what publishing a template uses.
Rotating the token
-
Generate a new token with the same scopes.
-
Replace the
GITHUB_TOKENline in~/.envon the control plane. -
Deploy Thinkube Control again, because it reads the file when it is deployed. From Thinkube IDE, run the
ansible/40_thinkube/core/thinkube-control/12_deploy.yamlplaybook of thethinkuberepository. -
In Thinkube IDE, run
gh auth login --with-tokenwith the new token. -
Revoke the old token on GitHub.
Next
-
Run the installer — the installer, screen by screen.