v16: automated service-account token rotation via the admin token API #75
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#75
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Tier 1 v16 follow-up (gated on #73 landing). v16 adds an instance-admin token-management API:
GET/POST/DELETE /api/v1/admin/users/{user}/tokensover normal site-admin token auth (PR 12323), with token creation dates in responses (PR 12620).This removes ADR 0024's worst step — the admin password-reset + Basic-auth dance to mint/revoke a PAT for a no-login service account — and enables automated, age-based PAT rotation for
gitborg-renovate,gitborg-reconciler,gitborg-runner-controllerandgitborg-ci.Scope:
/api/swaggerpost-upgrade). —read:adminverified against prod swagger 16.0.0; the token-audit run confirms it lists all accounts' tokens.token-auditrole (daily timer) exports token creation-time metrics;ForgejoTokenRotationDuealerts >80d. Live on prod.Delivered via PRs #96 (token-audit role + alerts), #108 (readability fix), #109 (vaulted PAT), bitborg-docs #36 (ADR 0024). Fully activated on prod 2026-07-18.
Note: v16's Authorized Integrations (JWT auth without static secrets) may eventually obsolete static PATs — tracked separately in #80, not blocking. Fully autonomous host-side rotation (a timer that mints+delivers without an operator) was deliberately deferred as an ADR-level change (would fight the vault-as-source-of-truth model); the age alert + one-command procedure covers the practical need.
Progress (branch
feat/75-token-rotation, PR pending push):Done
GET/POST/DELETE /api/v1/admin/users/{user}/tokensexist with normal token auth, andAccessTokenresponses carrycreated_at.write:admin(reconciler-style) covers mint/revoke;read:adminsuffices for listing.token-auditrole (daily user timer, reconciler shape) lists every service account's tokens and exportsgitborg_forgejo_token_created_timestamp_secondstextfile metrics.ForgejoTokenRotationDue(warning) fires when an account's newest token is >80d (alert_token_rotation_due_days);TokenAuditFailedcovers the audit itself. Auth = newgitborg-token-auditadmin account (ADR 0024 one-admin-per-automation) with a read:admin-only PAT — the audit can never mint or revoke.docs/75-adr-0024-token-api).Deliberately deferred: fully-autonomous host-side rotation. Every consumer re-renders its token from vault on each apply (
renovate.env,reconciler.env, runner-controller podman secret), so a host timer that mints+delivers new tokens makes the nextsite.ymlrun write the old, revoked token back — an outage generator. Going autonomous means moving the runtime source of truth from Vault to the host (create-if-missing semantics in 3 roles + self-rotation chicken-and-egg + crash-between-mint-and-deliver recovery) — an ADR-level change that deserves its own decision. The alert + one-command procedure gets ~90% of the value with none of that risk. If we still want full auto, propose it as a follow-up ADR.Remaining apply-day steps: apply
--tags forgejo(creates the account), mint the read:admin PAT, vault asvault_forgejo_token_audit_token, apply--tags token-audit,monitoring.