APP-2306: Add VITE_POSTHOG_CLIENT_KEY to Docker build (#1302)

* Add VITE_POSTHOG_CLIENT_KEY to Docker build

Bake the PostHog client key into the frontend bundle at build time by
accepting a VITE_POSTHOG_CLIENT_KEY build arg in the Dockerfile and
passing it from the Docker workflow via the POSTHOG_CLIENT_KEY repo
variable. The key is a public, client-side key (not a secret), following
the same pattern as VITE_APP_ENV.

Closes APP-2306

* Select staging/prod PostHog key by release tag

Mirror the VITE_APP_ENV logic for VITE_POSTHOG_CLIENT_KEY: tagged v*
releases bake the prod key, all other builds (PR/main/local) use staging.
Both keys are public client-side keys (not secrets) sourced from the
POSTHOG_CLIENT_KEY_PROD / POSTHOG_CLIENT_KEY_STAGING repo variables.

* Rename PostHog repo vars to POSTHOG_STAGING_KEY / POSTHOG_PROD_KEY
This commit is contained in:
aivong-openhands
2026-06-10 22:36:24 +00:00
committed by GitHub
parent 994912fbe7
commit 5076bb3517
2 changed files with 13 additions and 1 deletions
+8 -1
View File
@@ -105,6 +105,8 @@ jobs:
DEFAULT_AGENT_SERVER_IMAGE: ${{ steps.config.outputs.default_agent_server_image }}
AUTOMATION_VERSION_INPUT: ${{ inputs.automation_version }}
DEFAULT_AUTOMATION_VERSION: ${{ steps.config.outputs.default_automation_version }}
POSTHOG_STAGING_KEY: ${{ vars.POSTHOG_STAGING_KEY }}
POSTHOG_PROD_KEY: ${{ vars.POSTHOG_PROD_KEY }}
run: |
SHORT_SHA=$(echo "$RELEVANT_SHA" | cut -c1-7)
echo "short_sha=$SHORT_SHA" >> "$GITHUB_OUTPUT"
@@ -169,11 +171,15 @@ jobs:
echo "tags=$TAGS" >> "$GITHUB_OUTPUT"
# Use production PostHog key only for tagged releases
# Use the production PostHog config only for tagged releases;
# everything else (PR / main / local) uses staging. Both keys are
# public, client-side keys — not secrets — so they live in repo vars.
if [[ "$RELEVANT_REF" == refs/tags/v* ]]; then
echo "vite_app_env=production" >> "$GITHUB_OUTPUT"
echo "posthog_client_key=$POSTHOG_PROD_KEY" >> "$GITHUB_OUTPUT"
else
echo "vite_app_env=" >> "$GITHUB_OUTPUT"
echo "posthog_client_key=$POSTHOG_STAGING_KEY" >> "$GITHUB_OUTPUT"
fi
echo "=== Build outputs ==="
@@ -198,6 +204,7 @@ jobs:
OPENHANDS_BUILD_GIT_SHA=${{ env.RELEVANT_SHA }}
OPENHANDS_BUILD_GIT_REF=${{ env.RELEVANT_REF }}
VITE_APP_ENV=${{ steps.prep.outputs.vite_app_env }}
VITE_POSTHOG_CLIENT_KEY=${{ steps.prep.outputs.posthog_client_key }}
cache-from: type=gha
cache-to: type=gha,mode=max
provenance: true
+5
View File
@@ -39,8 +39,13 @@ COPY . .
# VITE_APP_ENV controls the PostHog telemetry key baked into the bundle:
# "production" → prod key (set by CI for tagged releases)
# anything else → staging key (default for PR / main / local builds)
# VITE_POSTHOG_CLIENT_KEY is the PostHog project key exposed via the web client
# config (option-service). Not a secret — it's a public, client-side key. CI
# passes the prod key for tagged releases and the staging key otherwise.
ARG VITE_APP_ENV=""
ARG VITE_POSTHOG_CLIENT_KEY=""
ENV VITE_APP_ENV=${VITE_APP_ENV}
ENV VITE_POSTHOG_CLIENT_KEY=${VITE_POSTHOG_CLIENT_KEY}
RUN npm run build
# ── Stage 1b: Generate shell-sourceable defaults from config/defaults.json ──