ADR 0024's token inventory has drifted from the estate #73
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs#73
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Follow-up recorded in
bitborg-infra#348, which could not do it — the decision record lives in thisrepository.
The token inventory in ADR 0024 has drifted from the estate it describes. Reconciled against
forgejo_service_accounts,group_vars/vault.example.ymland the live instance on 2026-08-02:Missing from the table
gitborg-webhook-admin— admin,read:admin, vault. Its single call isGET /api/v1/admin/hooks, verifying the reconcile-trigger system webhook (ADR 0037).gitborg-token-audit— admin,read:admin, vault. Mentioned in the Consequences prose but absentfrom the table, which is the part anyone actually reads as the inventory.
Wrong in the table
gitborg-ciis described as stored in the Actions store "(not vault)". It holds two tokens, onein each store: the vault copy drives the host-side registry mirror and the retention sweep, the
Actions copy drives bitborg-web's deploy. Rotation has to cover both, and the current wording
actively suggests it does not.
gitborg-botis described as "read-only MCP token + future narrow site-wide tokens". The futurearrived: it carries
read:packageas the org Actions secretREGISTRY_READ_TOKEN, used bybitborg-infra's own CI to pull mirrored images.
gitborg-runner-controllersays only "runner-controller admin PAT". The scope iswrite:admin,plus
write:repositoryif the run-cancel path is exercised.Missing as a concept
The audited account list is now derived from
forgejo_service_accountsrather than hand-kept(bitborg-infra#314). That is worth stating in the decision, because it is what makes "add an account
to the provisioning list" sufficient to bring its PAT under
ForgejoTokenRotationDue— and theduplication it replaced is exactly how
gitborg-webhook-adminstayed invisible.Done when
forgejo_service_accountsappears in the ADR tablegitborg-ci"not vault" claim is corrected