token inventory: ADR 0024 has drifted, and one write:admin PAT is invisible to token-audit #314
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#314
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Found while mapping the token inventory for #80. ADR 0024 is the record of which service accounts hold
which Forgejo tokens; several things have drifted from it, and one of them is a monitoring gap rather than
a documentation one.
The monitoring gap — the important one
gitborg-webhook-adminis absent from ADR 0024 entirely and from thetoken-auditlist. Itswrite:adminPAT is therefore the one credentialForgejoTokenRotationDuecannot see: nothing reportsits age, so it can quietly become the oldest admin-scoped token we hold.
Worth noting how little it needs: its only call is a read-only
GET /admin/hooks. So this is also aleast-privilege finding — a
write:admintoken doing a read-only job.The documentation drift
gitborg-token-auditappears in the ADR's prose but not in its table.gitborg-botholds a second real token (REGISTRY_READ_TOKEN) that the ADR does not mention.gitborg-ci'swrite:packagetoken exists in two places — the org Actions secret and a vault copyfor
registry-mirror— while the ADR says "not vault". Two copies of one credential is a rotationhazard: rotating one and not the other fails at a distance, and the ADR currently denies the second
copy exists.
vault.example.ymland the runbook.Done when
gitborg-webhook-admin,gitborg-token-auditand both ofgitborg-bot's tokens.gitborg-webhook-adminis covered bytoken-audit, so its age is visible toForgejoTokenRotationDuelike every other token.GET /admin/hooks— if a narrower scope suffices, use it; ifwrite:adminreally is the minimum Forgejo offers for that call, record that so the next reader doesnot re-open the question.
write:packagecredential is either de-duplicated or documented as intentionallyduplicated with both locations named, so rotation covers both.
The ADR itself lives in the separate
bitborg-docsrepository; thetoken-auditlist and scopes livehere, so closing this needs a change in each.