ci: smoke registry login uses gitborg-bot, not gitborg-ci (#137) #140

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/137-ci-login-gitborg-bot in i main 2026-07-19 11:49:01 +00:00
Ägare

Follow-up to #139 (part of #137). Corrects the CI mirror-login identity per the service-account model.

ci.yml logged in as gitborg-ci, but per forgejo_service_accounts (Option 2 — dedicated account per automation) gitborg-ci is isolated to the auto-deploy push path; reusing it for the CI mirror pull would break that isolation. Move the read-only login to gitborg-bot — the model's documented least-privilege catch-all "where new automation starts."

  • -u gitborg-ci → -u gitborg-bot; comment updated.
  • REGISTRY_READ_TOKEN = a read:package PAT on gitborg-bot, minted via an admin bot PAT (gitborg-reconciler/gitborg-runner-controller), never a personal account.

Valid YAML + prettier-clean. Still best-effort/non-fatal, so merging before the secret exists keeps CI green (upstream fallback). No prod apply needed — workflow-only.

Follow-up to #139 (part of #137). Corrects the CI mirror-login identity per the service-account model. `ci.yml` logged in as `gitborg-ci`, but per `forgejo_service_accounts` (Option 2 — dedicated account per automation) `gitborg-ci` is **isolated to the auto-deploy push path**; reusing it for the CI mirror *pull* would break that isolation. Move the read-only login to **`gitborg-bot`** — the model's documented least-privilege catch-all "where new automation starts." - `-u gitborg-ci` → `-u gitborg-bot`; comment updated. - `REGISTRY_READ_TOKEN` = a `read:package` PAT on **gitborg-bot**, minted via an **admin bot** PAT (`gitborg-reconciler`/`gitborg-runner-controller`), never a personal account. Valid YAML + prettier-clean. Still best-effort/non-fatal, so merging before the secret exists keeps CI green (upstream fallback). No prod apply needed — workflow-only.
supernaut lade till 1 incheckning 2026-07-19 11:41:55 +00:00
ci: smoke registry login uses gitborg-bot, not gitborg-ci (#137)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m20s
5db2fae308
Per the service-account model (group_vars: Option 2, dedicated account per
automation), gitborg-ci is isolated to the auto-deploy push path — reusing it for
the CI mirror pull would break that isolation. Move the read-only login to
gitborg-bot, the least-privilege catch-all where new automation starts. The
REGISTRY_READ_TOKEN secret is a read:package PAT on gitborg-bot, minted via an
admin bot PAT (never a personal account).
supernaut sammanfogade incheckning 91effd7101 till main 2026-07-19 11:49:01 +00:00
supernaut tog bort grenen fix/137-ci-login-gitborg-bot 2026-07-19 11:49:01 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!140
Ingen beskrivning angiven.