Reconciler: scope-short token silently no-ops Actions enforcement (make fatal/alertable) #183

Stängd
öppnade 2026-07-21 12:14:55 +00:00 av supernaut · 0 kommentarer
Ägare

Split out from #125 (finding H3) — the last fail-open path in the reconciler quota system.

set_repo_actions (ansible/roles/reconciler/templates/gitborg-reconciler.sh.j2:171-193) does WARN-and-return 0 on any non-200 response. If the reconciler token is missing read:user / write:repository, the Actions default-deny is never enforced and the run still exits 0 — a non-entitled user keeps CI (real OpenStack VM cost) with no alert.

Fix

  • Verify the live reconciler token's scopes against what set_repo_actions needs.
  • Make a scope/permission failure fatal (non-zero exit), or emit an alertable metric (e.g. reconciler_actions_enforce_failed) wired to a Grafana alert.

Context

Remaining tail of #125 after: H1/H2 → #164, M4 → #169, M8 → #166. The other sibling remainder (M3 — upload/file-size caps) stays on #125.

Split out from #125 (finding **H3**) — the last fail-open path in the reconciler quota system. `set_repo_actions` (`ansible/roles/reconciler/templates/gitborg-reconciler.sh.j2:171-193`) does WARN-and-`return 0` on any non-200 response. If the reconciler token is missing `read:user` / `write:repository`, the Actions default-deny is **never enforced** and the run still exits 0 — a non-entitled user keeps CI (real OpenStack VM cost) with **no alert**. ### Fix - Verify the live reconciler token's scopes against what `set_repo_actions` needs. - Make a scope/permission failure **fatal** (non-zero exit), **or** emit an alertable metric (e.g. `reconciler_actions_enforce_failed`) wired to a Grafana alert. ### Context Remaining tail of #125 after: H1/H2 → #164, M4 → #169, M8 → #166. The other sibling remainder (M3 — upload/file-size caps) stays on #125.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#183
Ingen beskrivning angiven.