docs(adr-0024): reconcile the token inventory with the estate #74
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-docs!74
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "docs/adr-0024-token-inventory"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #73. Follow-up from
bitborg-infra#348, which could not do it — the decision record liveshere.
Reconciled against
forgejo_service_accounts,group_vars/vault.example.ymland the live instanceon 2026-08-02.
Added
gitborg-webhook-admin— admin,read:admin, vault. One read-only call,GET /api/v1/admin/hooks, verifying the reconcile-trigger system webhook (ADR 0037).gitborg-token-audit— admin,read:admin, vault. It was described in the Consequences prosebut absent from the table, which is the part anyone reads as the inventory.
Corrected
gitborg-cisaid "not vault". It holds twowrite:packagetokens, one in each store: thevault copy drives the host-side registry mirror and the retention sweep, the Actions copy drives
bitborg-web's deploy. Rotation must cover both — replacing one leaves the other working, so the
miss surfaces later and somewhere else. The old wording actively suggested there was nothing in
the vault to rotate.
gitborg-botwas "read-only MCP token + future narrow site-wide tokens". The future arrived:it carries
read:packageas the org Actions secretREGISTRY_READ_TOKEN, used by bitborg-infra'sown CI to pull mirrored images.
gitborg-runner-controllersaid only "runner-controller admin PAT". The scope iswrite:admin, pluswrite:repositoryif the run-cancel path is exercised.Structural change
Where a token lives is now a column, not a footnote, because it is what decides how the token is
rotated: a vault token is a vault edit plus an apply, an Actions-store token is a
PUT …/actions/secrets/<NAME>. Reading the store off the same row as the scope is what makes"rotate this" an unambiguous instruction.
Also recorded, as part of the Decision rather than a caveat: the audited account list is derived
from
forgejo_service_accountsrather than hand-kept (bitborg-infra#314). That is what makesadding an account to the provisioning list sufficient to bring its PAT under
ForgejoTokenRotationDue, and the duplication it replaced is exactly howgitborg-webhook-admincame to hold an admin-scoped PAT whose age nothing reported.
One thing worth reading before the next rotation
The table now states the expected token counts —
gitborg-ci2 andgitborg-bot2 — and says acount above what the table explains is a stale token that was never revoked. That is not
hypothetical: the audit currently reports 2 on
gitborg-reconcilerand 2 ongitborg-webhook-admin,neither of which this table explains. The rotation procedure mints the replacement before revoking
the old one, and the revoke step is the one that gets skipped.
markdownlint and Prettier clean.