v16 eval: Authorized Integrations (JWT auth) vs static service-account PATs #80
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#80
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Tier 2 v16 follow-up — evaluation (gated on #73 landing). v16 introduces Authorized Integrations: JWT-based authentication for the API and Git that avoids long-lived static secrets (from the v16.0 release announcement; not in our original upgrade plan — discovered during release-day verification).
Evaluate whether it can reduce or replace our static-PAT surface:
Outcome: a short findings note + go/no-go per consumer; ADR update only if adopted.
Eval done — recommendation: DEFER broad adoption; adopt for one subset only (
gitborg-ciin-Actions package push) as a scoped PoC.How it works (v16): Authorized Integrations is inbound auth — a trust rule asserts on an incoming JWT (issuer via OIDC discovery + JWKS, Forgejo-generated audience, claim matching eq/in/glob/nest) and authenticates the caller as a user with access-token-equivalent scopes, no shared secret. The caller must present a JWT from a trusted issuer: local Forgejo Actions (
urn:forgejo:authorized-integrations:actions, ~1hID_TOKEN_EXPIRATION_TIME) or an external OIDC provider (AWS/GitHub/GitLab). Docs do not cover a plain standalone script obtaining such a JWT.Mapping vs ADR 0024:
REGISTRY_TOKEN.Rotation (#75): moot only for whatever moves to JWT (i.e. gitborg-ci if adopted); stays load-bearing for all the host-script bots. ADR change: none now — only a short ADR 0024 addendum if the gitborg-ci PoC lands.
Verify on the instance: (1) package registry accepts the Actions JWT for
write:package; (2) JWT-auth calls appear distinctly in the v16 audit log; (3) whether Kanidm can be a trusted issuer for host automation.Full note:
bitborg-internal/plans/2026-07-20-authorized-integrations-jwt-eval.md.