ADR 0024's token inventory has drifted from the estate #73

Stängd
öppnade 2026-08-02 19:16:16 +00:00 av supernaut · 0 kommentarer
Ägare

Follow-up recorded in bitborg-infra#348, which could not do it — the decision record lives in this
repository.

The token inventory in ADR 0024 has drifted from the estate it describes. Reconciled against
forgejo_service_accounts, group_vars/vault.example.yml and the live instance on 2026-08-02:

Missing from the table

  • gitborg-webhook-admin — admin, read:admin, vault. Its single call is
    GET /api/v1/admin/hooks, verifying the reconcile-trigger system webhook (ADR 0037).
  • gitborg-token-audit — admin, read:admin, vault. Mentioned in the Consequences prose but absent
    from the table, which is the part anyone actually reads as the inventory.

Wrong in the table

  • gitborg-ci is described as stored in the Actions store "(not vault)". It holds two tokens, one
    in each store: the vault copy drives the host-side registry mirror and the retention sweep, the
    Actions copy drives bitborg-web's deploy. Rotation has to cover both, and the current wording
    actively suggests it does not.
  • gitborg-bot is described as "read-only MCP token + future narrow site-wide tokens". The future
    arrived: it carries read:package as the org Actions secret REGISTRY_READ_TOKEN, used by
    bitborg-infra's own CI to pull mirrored images.
  • gitborg-runner-controller says only "runner-controller admin PAT". The scope is write:admin,
    plus write:repository if the run-cancel path is exercised.

Missing as a concept

The audited account list is now derived from forgejo_service_accounts rather than hand-kept
(bitborg-infra#314). That is worth stating in the decision, because it is what makes "add an account
to the provisioning list" sufficient to bring its PAT under ForgejoTokenRotationDue — and the
duplication it replaced is exactly how gitborg-webhook-admin stayed invisible.

Done when

  • Every account in forgejo_service_accounts appears in the ADR table
  • Each row records where the token lives, since that is what decides how it is rotated
  • The gitborg-ci "not vault" claim is corrected
Follow-up recorded in `bitborg-infra#348`, which could not do it — the decision record lives in this repository. The token inventory in ADR 0024 has drifted from the estate it describes. Reconciled against `forgejo_service_accounts`, `group_vars/vault.example.yml` and the live instance on 2026-08-02: **Missing from the table** - `gitborg-webhook-admin` — admin, `read:admin`, vault. Its single call is `GET /api/v1/admin/hooks`, verifying the reconcile-trigger system webhook (ADR 0037). - `gitborg-token-audit` — admin, `read:admin`, vault. Mentioned in the Consequences prose but absent from the table, which is the part anyone actually reads as the inventory. **Wrong in the table** - `gitborg-ci` is described as stored in the Actions store "(not vault)". It holds **two** tokens, one in each store: the vault copy drives the host-side registry mirror and the retention sweep, the Actions copy drives bitborg-web's deploy. Rotation has to cover both, and the current wording actively suggests it does not. - `gitborg-bot` is described as "read-only MCP token + future narrow site-wide tokens". The future arrived: it carries `read:package` as the org Actions secret `REGISTRY_READ_TOKEN`, used by bitborg-infra's own CI to pull mirrored images. - `gitborg-runner-controller` says only "runner-controller admin PAT". The scope is `write:admin`, plus `write:repository` if the run-cancel path is exercised. **Missing as a concept** The audited account list is now *derived* from `forgejo_service_accounts` rather than hand-kept (bitborg-infra#314). That is worth stating in the decision, because it is what makes "add an account to the provisioning list" sufficient to bring its PAT under `ForgejoTokenRotationDue` — and the duplication it replaced is exactly how `gitborg-webhook-admin` stayed invisible. ## Done when - [ ] Every account in `forgejo_service_accounts` appears in the ADR table - [ ] Each row records where the token lives, since that is what decides how it is rotated - [ ] The `gitborg-ci` "not vault" claim is corrected
supernaut lade till detta till projektet Bitborg Docs 2026-08-02 19:16:59 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-docs#73
Ingen beskrivning angiven.