registry: split the shared CI token between mirror and retention #463

Öppen
öppnade 2026-09-08 23:04:26 +00:00 av supernaut · 0 kommentarer
Ägare

vault_forgejo_ci_token is used by both registry-mirror (REGISTRY_MIRROR_TOKEN) and registry-retention (FORGEJO_TOKEN). Neither can be rotated or revoked on its own, and token-audit cannot attribute usage to a consumer.

Mint two scoped tokens (mirror: package write; retention: package read and delete), add two vault values, and point each role's env template at its own. Coordinate with the token-audit role's expected-token list.

`vault_forgejo_ci_token` is used by both `registry-mirror` (`REGISTRY_MIRROR_TOKEN`) and `registry-retention` (`FORGEJO_TOKEN`). Neither can be rotated or revoked on its own, and `token-audit` cannot attribute usage to a consumer. Mint two scoped tokens (mirror: package write; retention: package read and delete), add two vault values, and point each role's env template at its own. Coordinate with the token-audit role's expected-token list.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#463
Ingen beskrivning angiven.