rotate reconciler token with read:organization + document org scope (#37) #173

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/reconciler-token-org-scope in i main 2026-07-20 15:05:18 +00:00
Ägare

Follow-up to #37 (org Actions gating). The reconciler now lists org repos to gate their actions unit, which needs the Forgejo scope read:organization — the dedicated reconciler token lacked it, so GET /orgs/gitborg/repos returned 403 and the org gating best-effort-skipped.

Already applied + verified on prod (this PR captures the state):

  • Rotated vault_forgejo_reconciler_token to write:admin,read:user,write:repository,read:organization (minted under the gitborg-reconciler service account, ADR 0024). vault.yml here is the new encrypted blob (still $ANSIBLE_VAULT;1.1;AES256).
  • Applied --tags reconciler; reconciler now runs clean — no HTTP 403 / skipping Actions toggle WARN; org bitborg: quota=org-unlimited actions=true.

Runbook: the token-scope note + mint command now include read:organization and the gitborg-reconciler service account, plus the --tags reconciler re-apply/verify steps (the old command listed only three scopes and would reintroduce the 403).

⚠️ Prod already runs this rotated token; merge promptly so a re-apply from main doesn't revert to the old (pre-read:organization) token. Closes the #125 M4 / #37 token-scope gap (H3).

Follow-up to #37 (org Actions gating). The reconciler now lists org repos to gate their `actions` unit, which needs the Forgejo scope `read:organization` — the dedicated reconciler token lacked it, so `GET /orgs/gitborg/repos` returned 403 and the org gating best-effort-skipped. **Already applied + verified on prod** (this PR captures the state): - Rotated `vault_forgejo_reconciler_token` to `write:admin,read:user,write:repository,read:organization` (minted under the `gitborg-reconciler` service account, ADR 0024). `vault.yml` here is the new **encrypted** blob (still `$ANSIBLE_VAULT;1.1;AES256`). - Applied `--tags reconciler`; reconciler now runs clean — no `HTTP 403` / `skipping Actions toggle` WARN; `org bitborg: quota=org-unlimited actions=true`. **Runbook:** the token-scope note + mint command now include `read:organization` and the `gitborg-reconciler` service account, plus the `--tags reconciler` re-apply/verify steps (the old command listed only three scopes and would reintroduce the 403). ⚠️ Prod already runs this rotated token; **merge promptly** so a re-apply from `main` doesn't revert to the old (pre-`read:organization`) token. Closes the #125 M4 / #37 token-scope gap (H3).
supernaut lade till 1 incheckning 2026-07-20 14:59:15 +00:00
chore(reconciler): rotate token with read:organization + document org scope (#37)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m44s
d2dfc2f258
The reconciler now gates the Actions unit on org repos (#37), which needs
read:organization to list them — the token was missing it, so org listing
403'd and org gating no-op'd. Rotated vault_forgejo_reconciler_token to
write:admin,read:user,write:repository,read:organization (applied + verified
on prod: no more HTTP 403, org Actions gating enforces).

- vault.yml: rotated encrypted reconciler token (still age/vault-encrypted)
- runbook: mint command adds read:organization + gitborg-reconciler service
  account + the --tags reconciler re-apply/verify steps
supernaut sammanfogade incheckning 2f06ff2061 till main 2026-07-20 15:05:18 +00:00
supernaut tog bort grenen chore/reconciler-token-org-scope 2026-07-20 15:05:18 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!173
Ingen beskrivning angiven.