token inventory: ADR 0024 has drifted, and one write:admin PAT is invisible to token-audit #314

Stängd
öppnade 2026-08-01 15:00:44 +00:00 av supernaut · 0 kommentarer
Ägare

Found while mapping the token inventory for #80. ADR 0024 is the record of which service accounts hold
which Forgejo tokens; several things have drifted from it, and one of them is a monitoring gap rather than
a documentation one.

The monitoring gap — the important one

gitborg-webhook-admin is absent from ADR 0024 entirely and from the token-audit list. Its
write:admin PAT is therefore the one credential ForgejoTokenRotationDue cannot see: nothing reports
its age, so it can quietly become the oldest admin-scoped token we hold.

Worth noting how little it needs: its only call is a read-only GET /admin/hooks. So this is also a
least-privilege finding — a write:admin token doing a read-only job.

The documentation drift

  • gitborg-token-audit appears in the ADR's prose but not in its table.
  • gitborg-bot holds a second real token (REGISTRY_READ_TOKEN) that the ADR does not mention.
  • gitborg-ci's write:package token exists in two places — the org Actions secret and a vault copy
    for registry-mirror — while the ADR says "not vault". Two copies of one credential is a rotation
    hazard: rotating one and not the other fails at a distance, and the ADR currently denies the second
    copy exists.
  • Two scope/comment inconsistencies between vault.example.yml and the runbook.

Done when

  • The ADR's table matches what the repo actually provisions, including gitborg-webhook-admin,
    gitborg-token-audit and both of gitborg-bot's tokens.
  • gitborg-webhook-admin is covered by token-audit, so its age is visible to
    ForgejoTokenRotationDue like every other token.
  • Its scope is reconsidered against GET /admin/hooks — if a narrower scope suffices, use it; if
    write:admin really is the minimum Forgejo offers for that call, record that so the next reader does
    not re-open the question.
  • The duplicated write:package credential is either de-duplicated or documented as intentionally
    duplicated with both locations named, so rotation covers both.

The ADR itself lives in the separate bitborg-docs repository; the token-audit list and scopes live
here, so closing this needs a change in each.

Found while mapping the token inventory for #80. ADR 0024 is the record of which service accounts hold which Forgejo tokens; several things have drifted from it, and one of them is a monitoring gap rather than a documentation one. ## The monitoring gap — the important one **`gitborg-webhook-admin` is absent from ADR 0024 entirely and from the `token-audit` list.** Its `write:admin` PAT is therefore the one credential `ForgejoTokenRotationDue` cannot see: nothing reports its age, so it can quietly become the oldest admin-scoped token we hold. Worth noting how little it needs: its only call is a read-only `GET /admin/hooks`. So this is also a least-privilege finding — a `write:admin` token doing a read-only job. ## The documentation drift - `gitborg-token-audit` appears in the ADR's prose but not in its table. - `gitborg-bot` holds a second real token (`REGISTRY_READ_TOKEN`) that the ADR does not mention. - `gitborg-ci`'s `write:package` token exists in **two** places — the org Actions secret and a vault copy for `registry-mirror` — while the ADR says "not vault". Two copies of one credential is a rotation hazard: rotating one and not the other fails at a distance, and the ADR currently denies the second copy exists. - Two scope/comment inconsistencies between `vault.example.yml` and the runbook. ## Done when - The ADR's table matches what the repo actually provisions, including `gitborg-webhook-admin`, `gitborg-token-audit` and both of `gitborg-bot`'s tokens. - `gitborg-webhook-admin` is covered by `token-audit`, so its age is visible to `ForgejoTokenRotationDue` like every other token. - Its scope is reconsidered against `GET /admin/hooks` — if a narrower scope suffices, use it; if `write:admin` really is the minimum Forgejo offers for that call, record that so the next reader does not re-open the question. - The duplicated `write:package` credential is either de-duplicated or documented as intentionally duplicated **with both locations named**, so rotation covers both. The ADR itself lives in the separate `bitborg-docs` repository; the `token-audit` list and scopes live here, so closing this needs a change in each.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#314
Ingen beskrivning angiven.