feat(token-audit): age-based service-account token monitoring (#75) #96
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!96
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/75-token-rotation"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Refs #75 (doesn't close it — the account + PAT mint + apply are operator steps; see the issue comment for the full status and the deliberate deferral of fully-autonomous rotation).
What this adds
token-auditrole (observe-only, reconciler shape): daily systemd user timer lists each ADR 0024 service account's tokens via the v16 admin token API and writes textfile metrics (gitborg_forgejo_token_created_timestamp_seconds{account,token_name,token_id},gitborg_forgejo_token_count, run status/timestamp). Inert untilvault_forgejo_token_audit_tokenis set.gitborg-token-auditservice account (admin role — listing other users' tokens requires the admin API — but its PAT is mintedread:adminonly, so the audit can never mint/revoke).ForgejoTokenRotationDue(newest token per account > 80d,alert_token_rotation_due_days) andTokenAuditFailed.docs/75-adr-0024-token-api): basic-auth caveat superseded.Why not fully-autonomous rotation (issue's "rotation timer")
Every consumer role re-renders its token from vault on apply — host-side rotation would be clobbered by the next
site.ymlrun (old revoked token written back → outage). Moving runtime truth to the host is an ADR-level change (create-if-missing in 3 roles, self-rotation bootstrap, crash recovery). Deferred with rationale on the issue; alert + one-command procedure captures most of the value.Verification
created_atinAccessToken.fromdateiso8601chokes on; label values sanitized).ansible-playbook --syntax-check+ansible-lint(token-audit, monitoring): clean.Apply-day (after merge)
site.yml --tags forgejo→ createsgitborg-token-audit.POST /api/v1/admin/users/gitborg-token-audit/tokens {"name":"token-audit-YYYYMMDD","scopes":["read:admin"]}.vault_forgejo_token_audit_token;site.yml --tags token-audit,monitoring.systemctl --user start gitborg-token-audit.serviceonce and checktoken-audit.prom.991f477d70f4e2a07bc7f4e2a07bc7a42022412e