rotate reconciler token with read:organization + document org scope (#37) #173
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!173
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/reconciler-token-org-scope"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Follow-up to #37 (org Actions gating). The reconciler now lists org repos to gate their
actionsunit, which needs the Forgejo scoperead:organization— the dedicated reconciler token lacked it, soGET /orgs/gitborg/reposreturned 403 and the org gating best-effort-skipped.Already applied + verified on prod (this PR captures the state):
vault_forgejo_reconciler_tokentowrite:admin,read:user,write:repository,read:organization(minted under thegitborg-reconcilerservice account, ADR 0024).vault.ymlhere is the new encrypted blob (still$ANSIBLE_VAULT;1.1;AES256).--tags reconciler; reconciler now runs clean — noHTTP 403/skipping Actions toggleWARN;org bitborg: quota=org-unlimited actions=true.Runbook: the token-scope note + mint command now include
read:organizationand thegitborg-reconcilerservice account, plus the--tags reconcilerre-apply/verify steps (the old command listed only three scopes and would reintroduce the 403).⚠️ Prod already runs this rotated token; merge promptly so a re-apply from
maindoesn't revert to the old (pre-read:organization) token. Closes the #125 M4 / #37 token-scope gap (H3).