ci: smoke registry login uses gitborg-bot, not gitborg-ci (#137) #140
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!140
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/137-ci-login-gitborg-bot"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Follow-up to #139 (part of #137). Corrects the CI mirror-login identity per the service-account model.
ci.ymllogged in asgitborg-ci, but perforgejo_service_accounts(Option 2 — dedicated account per automation)gitborg-ciis isolated to the auto-deploy push path; reusing it for the CI mirror pull would break that isolation. Move the read-only login togitborg-bot— the model's documented least-privilege catch-all "where new automation starts."-u gitborg-ci→-u gitborg-bot; comment updated.REGISTRY_READ_TOKEN= aread:packagePAT on gitborg-bot, minted via an admin bot PAT (gitborg-reconciler/gitborg-runner-controller), never a personal account.Valid YAML + prettier-clean. Still best-effort/non-fatal, so merging before the secret exists keeps CI green (upstream fallback). No prod apply needed — workflow-only.