diff --git a/.crow/build.yaml b/.crow/build.yaml index 1d7cb47..b3b6c0e 100644 --- a/.crow/build.yaml +++ b/.crow/build.yaml @@ -158,11 +158,23 @@ steps: - name: Check which R versions already exist in s3 image: reg.devxy.io/docker.io/library/alpine:3.23 privileged: true + environment: + AWS_ACCESS_KEY_ID: + from_secret: B2_S3_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY: + from_secret: B2_S3_SECRET_KEY commands: - ip link set dev eth0 mtu 1280 2>/dev/null || true - for i in 1 2 3 4 5; do apk add -q --no-cache curl && break; sleep 5; done - | - LISTING=$(curl -s "https://s3.eu-central-003.backblazeb2.com/devxy-r-builds?prefix=${PLATFORM_ID}/" | \ + # Backblaze B2 requires authentication for the list-bucket API (anonymous + # GET works only for individual public-read objects), so the request must be + # SigV4-signed with the same credentials used for the upload step. Without + # this the listing returns AccessDenied, r-versions-existing.txt stays empty, + # and every version is rebuilt even though it already exists. + LISTING=$(curl -s --aws-sigv4 "aws:amz:eu-central-003:s3" \ + --user "${AWS_ACCESS_KEY_ID}:${AWS_SECRET_ACCESS_KEY}" \ + "https://s3.eu-central-003.backblazeb2.com/devxy-r-builds?prefix=${PLATFORM_ID}/" | \ grep -oE '[^<]+' | sed 's/<[^>]*>//g') : > r-versions-existing.txt for VERSION in $(cat r-versions-to-build.txt); do