docs(runbook): mint service-account PATs via an admin bot, not a personal account #141
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!141
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "docs/admin-bot-pat-policy"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Codifies the policy set while wiring up the CI registry-read token (#137): the admin token API's § Rotate a service-account PAT said to authenticate with "e.g. your own" admin PAT.
Change: require a
write:adminPAT from a dedicated admin bot (gitborg-reconciler/gitborg-runner-controller, from the vault) — never a human's personal admin token. Keeps admin automation attributable to a bot, avoids spreading a personal credential, and matches the Option-2forgejo_service_accountsmodel. Also renames the example$YOUR_ADMIN_PAT→$ADMIN_BOT_PAT.Docs-only; prettier + markdownlint clean. No CI/apply impact.