Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

SettleMint logo

SettleMint Github Action

https://settlemint.com
Integrate SettleMint into your application with ease.


CI statusstars

Description

This GitHub Action allows you to execute SettleMint CLI commands in your GitHub Actions workflow. It handles installation, authentication, and execution of CLI commands with proper environment configuration.

Features

  • 🚀 Automatic installation of SettleMint CLI
  • 🔐 Built-in authentication handling
  • 🌍 Support for all SettleMint environment variables
  • 📦 Version control for CLI installation
  • 🔌 Automatic workspace connection

Usage

Basic Example

steps:
- uses: actions/checkout@v4
- name: Run SettleMint CLIuses: settlemint/settlemint-action@mainwith:
command: "platform list workspaces"access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}

Advanced Example

steps:
- uses: actions/checkout@v4
- name: Deploy Smart Contractuses: settlemint/settlemint-action@mainwith:
command: "scs hardhat deploy remote --accept-defaults"access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}version: "1.0.0"workspace: "my-workspace-ae70"blockchain-node: "my-node-3b8e"auto-connect: "true"

Inputs

Required

InputDescriptionRequired
access-tokenSettleMint Access Token (can be a personal or an application access token)Yes

Optional

InputDescriptionDefault
commandCLI command to execute-
versionCLI version to install'latest'
auto-connectAutomatically connect to workspace'true' (personal access token) 'false' (application access token)
instanceSettleMint instance URL'https://console.settlemint.com'
workspaceWorkspace unique name-
applicationApplication unique name-
blockchain-networkBlockchain network unique name-
blockchain-nodeBlockchain node unique name-
load-balancerLoad balancer unique name-
hasuraHasura unique name-
thegraphTheGraph unique name-
portalPortal unique name-
hd-private-keyHD private key-
minioMinIO unique name-
ipfsIPFS unique name-
custom-deploymentCustom deployment unique name-
blockscoutBlockscout unique name-
dotEnvFile.env file content (store in secrets)-
dotEnvLocalFile.env.local file content (store in secrets)-

Common Use Cases

Deploying Smart Contracts

- name: Deploy Contractuses: settlemint/settlemint-action@mainwith:
command: scs hardhat deploy remote --accept-defaultsaccess-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}workspace: ${{ vars.WORKSPACE_UNIQUE_NAME }}

Managing Workspaces

- name: List Workspacesuses: settlemint/settlemint-action@mainwith:
command: platform list workspacesaccess-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}

Custom Version Installation

- name: Use Specific CLI Versionuses: settlemint/settlemint-action@mainwith:
command: --versionversion: "1.0.0"access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}

Environment Variables

All inputs are automatically converted to environment variables with the SETTLEMINT_ prefix. For example:

  • workspaceSETTLEMINT_WORKSPACE
  • blockchain-networkSETTLEMINT_BLOCKCHAIN_NETWORK

Environment Files

The action supports loading environment variables from .env files. You can provide the content of your env files through the following inputs:

  • dotEnvFile: Content of your main .env file
  • dotEnvLocalFile: Content of your .env.local file

⚠️Important: Always store env file contents in GitHub Secrets:

steps:
- uses: settlemint/settlemint-action@mainwith:
dotEnvFile: ${{ secrets.MY_ENV_FILE }}dotEnvLocalFile: ${{ secrets.MY_ENV_LOCAL }}access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}

The action will process these files and add all variables to the GitHub Actions environment. It handles:

  • Comments (lines starting with #)
  • Empty lines
  • Quoted values
  • Values containing = signs
  • Trailing comments

Error Handling

The action will fail if:

  • Invalid access token is provided
  • Required inputs are missing
  • CLI command execution fails
  • Network connectivity issues occur

Security

  • Never commit your access token directly in workflows
  • Use GitHub Secrets for sensitive information
  • Consider using OIDC for token management in production

Security Best Practices

Handling Secrets 🔒

  • NEVER commit access tokens, private keys or any secrets directly in your workflow files or repository

  • ALWAYS use GitHub Secrets for sensitive information:

    # ✅ CORRECT - Using GitHub Secretsaccess-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}# ❌ WRONG - NEVER do thisaccess-token: "your-token-here"# This is a security risk!
  • Use GitHub's OIDC (OpenID Connect) for token management in production environments

  • Regularly rotate your access tokens and secrets

  • Limit secret access to only the necessary workflows and repositories

Environment Variables

When using .env files:

steps:
- uses: settlemint/settlemint-action@mainwith:
dotEnvFile: ${{ secrets.ENV_FILE_CONTENT }} # Store as a secret!access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}

Troubleshooting

Common Issues

Invalid Access Token

Error: Failed to authenticate with SettleMint: Error: Process completed with exit code 1. Please check your access token.

Solution:

  • Ensure your access token is correctly stored in GitHub Secrets
  • Verify the token hasn't expired
  • Check that you're using the correct token format:
    • Personal Access Tokens: sm_pat_xxxxx
    • Application Tokens: sm_app_xxxxx

Command Injection Prevention

Error: Command contains potentially dangerous characters. Please use simple commands only.

Solution:

  • Avoid using shell operators like &&, ||, ;, |, or backticks
  • Use simple, direct commands
  • If you need to run multiple commands, use multiple action steps

Version Installation Failures

Error: Invalid version format: x.x.x. Must be a valid semver version or 'latest'

Solution:

  • Use valid semantic version numbers (e.g., 1.0.0, 2.1.3)
  • Use latest for the most recent version
  • Don't use version ranges or npm tags other than latest

Environment Variable Issues

Problem: Environment variables from .env files aren't being loaded

Solution:

  • Ensure the env file content is stored in GitHub Secrets
  • Check that the file content follows the correct format:
    KEY=value
    # Comments are supported
    QUOTED_VALUE="value with spaces"
    
  • Verify no shell metacharacters are in your values

CLI Not Found

Error: settlemint: command not found

Solution:

  • The action should automatically install the CLI
  • If using a self-hosted runner, ensure npm is available
  • Check the action logs for installation errors

Debugging Tips

  1. Enable Debug Logging:

    - name: Run SettleMint CLIuses: settlemint/settlemint-action@mainenv:
    ACTIONS_STEP_DEBUG: truewith:
    command: "your-command"access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}
  2. Check Token Format: Personal access tokens start with sm_pat_, while application tokens start with sm_app_. The action behaves differently based on the token type.

  3. Verify Workspace Connection: If auto-connect fails, try connecting manually first:

    - name: Connect to Workspaceuses: settlemint/settlemint-action@mainwith:
    command: "connect -w your-workspace-id"access-token: ${{ secrets.SETTLEMINT_ACCESS_TOKEN }}
  4. Cache Issues: The action caches CLI installations. If you experience issues, the cache will be automatically invalidated when changing versions.

Contributing

Contributions are welcome! Please read our Contributing Guide for details on our code of conduct and the process for submitting pull requests.

License

This project is licensed under the FSL-1.1-MIT License - see the LICENSE file for details.

Support

About

Interact with the SettleMint platform in Github Actions

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages