chore(vault): rotate Forgejo internal secrets + prune orphaned vault keys #216
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!216
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/rotate-forgejo-secrets-vault-hygiene"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Secret rotation + vault hygiene (no code changes).
Rotated (hashed-name podman secrets; applied to prod, Forgejo restarted cleanly):
vault_forgejo_internal_tokenvault_forgejo_jwt_secret(oauth2)vault_forgejo_lfs_jwt_secretvault_forgejo_metrics_token(+ themonitoring-agentvmagent scrape token, kept in sync)SECRET_KEY, the DB password, and the mailer password were deliberately not rotated in this pass(SECRET_KEY encrypts at-rest data — SSO source / 2FA / Actions secrets — so it's handled separately).
Pruned orphaned keys from
vault.yml+vault.example.yml(referenced nowhere in the code):vault_forgejo_admin_token(superseded by the Kanidm web-provision flow, ADR 0014 Ph2)vault_forgejo_runner_uuid/_runner_token/_build_runner_uuid/_build_runner_token(legacy static-runner registration, superseded by the ephemeral runner-controller, ADR 0021)
vault_backup_encryption_passphrase(legacy openssl backup passphrase, superseded by age; verifiedzero remaining
.tar.encarchives locally + off-site)vault.example.ymlre-synced to exactly match the code-referenced keys.vault.ymlcommitted encrypted.Verified in prod post-apply: Forgejo
active+ restarted with the new secrets, no log errors, allendpoints 200 (git / www / auth-SSO), the Forgejo metrics scrape
up=1(metrics-token rotation clean),no down scrape targets, and no firing alerts beyond the intentional Watchdog.