Caddy v2 middleware for validating a GitHub webhook request.
xcaddy build \
--with github.com/layer8co/caddy-validate-github
This middleware functions as a gatekeeper for any succeeding directives in a route. The request is only passed on to the next directive if its signature is valid. Otherwise, the client receives a 403 status code.
validate_github_webhook <secret>
- secret - shared secret between you and GitHub
You could use a tool like openssl to generate a secure secret:
openssl rand -hex 12validate_github_webhook is a middleware meant to precede other directives.
An example of this directive in context looks like this:
route /update {
validate_github_webhook KcuP9N0iEqYHFBRUda6oHLP4UUub6EMz
exec * /path/to/bin/deploy.sh
}
Here, you're using validate_github to validate the request before passing
it along to caddy-exec, runs the
/path/to/bin/deploy.sh script. Since caddy-exec does not support chaining
commands at this time, it's necessary to perform multiple commands in a script
or Go binary and invoke it from the exec directive.
By using the module in this way, it can act as a simple continues-deployment solution.
The validate_github_webhook JSON look like this, minus succeeding middleware:
{
"routes": [
{
"handle": [
{
"handler": "validate_github_webhook",
"secret": "KcuP9N0iEqYHFBRUda6oHLP4UUub6EMz"
}
],
"match": [
{
"path": [
"/refresh"
]
}
]
}
]
}Main credit goes to Adam woodbeck, the original creator of the module.