chore(vault): rotate Forgejo internal secrets + prune orphaned vault keys #216

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/rotate-forgejo-secrets-vault-hygiene in i main 2026-07-24 14:05:55 +00:00
Ägare

Secret rotation + vault hygiene (no code changes).

Rotated (hashed-name podman secrets; applied to prod, Forgejo restarted cleanly):

  • vault_forgejo_internal_token
  • vault_forgejo_jwt_secret (oauth2)
  • vault_forgejo_lfs_jwt_secret
  • vault_forgejo_metrics_token (+ the monitoring-agent vmagent scrape token, kept in sync)

SECRET_KEY, the DB password, and the mailer password were deliberately not rotated in this pass
(SECRET_KEY encrypts at-rest data — SSO source / 2FA / Actions secrets — so it's handled separately).

Pruned orphaned keys from vault.yml + vault.example.yml (referenced nowhere in the code):

  • vault_forgejo_admin_token (superseded by the Kanidm web-provision flow, ADR 0014 Ph2)
  • vault_forgejo_runner_uuid / _runner_token / _build_runner_uuid / _build_runner_token
    (legacy static-runner registration, superseded by the ephemeral runner-controller, ADR 0021)
  • vault_backup_encryption_passphrase (legacy openssl backup passphrase, superseded by age; verified
    zero remaining .tar.enc archives locally + off-site)

vault.example.yml re-synced to exactly match the code-referenced keys. vault.yml committed encrypted.

Verified in prod post-apply: Forgejo active + restarted with the new secrets, no log errors, all
endpoints 200 (git / www / auth-SSO), the Forgejo metrics scrape up=1 (metrics-token rotation clean),
no down scrape targets, and no firing alerts beyond the intentional Watchdog.

Secret rotation + vault hygiene (no code changes). **Rotated** (hashed-name podman secrets; applied to prod, Forgejo restarted cleanly): - `vault_forgejo_internal_token` - `vault_forgejo_jwt_secret` (oauth2) - `vault_forgejo_lfs_jwt_secret` - `vault_forgejo_metrics_token` (+ the `monitoring-agent` vmagent scrape token, kept in sync) `SECRET_KEY`, the DB password, and the mailer password were deliberately **not** rotated in this pass (SECRET_KEY encrypts at-rest data — SSO source / 2FA / Actions secrets — so it's handled separately). **Pruned orphaned keys** from `vault.yml` + `vault.example.yml` (referenced nowhere in the code): - `vault_forgejo_admin_token` (superseded by the Kanidm web-provision flow, ADR 0014 Ph2) - `vault_forgejo_runner_uuid` / `_runner_token` / `_build_runner_uuid` / `_build_runner_token` (legacy static-runner registration, superseded by the ephemeral runner-controller, ADR 0021) - `vault_backup_encryption_passphrase` (legacy openssl backup passphrase, superseded by age; verified zero remaining `.tar.enc` archives locally + off-site) `vault.example.yml` re-synced to exactly match the code-referenced keys. `vault.yml` committed encrypted. **Verified in prod post-apply:** Forgejo `active` + restarted with the new secrets, no log errors, all endpoints 200 (git / www / auth-SSO), the Forgejo metrics scrape `up=1` (metrics-token rotation clean), no down scrape targets, and no firing alerts beyond the intentional Watchdog.
supernaut lade till 1 incheckning 2026-07-24 12:34:40 +00:00
chore(vault): rotate Forgejo internal secrets + prune orphaned vault keys
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m25s
340aaaa26d
supernaut sammanfogade incheckning d5d969d769 till main 2026-07-24 14:05:55 +00:00
supernaut tog bort grenen chore/rotate-forgejo-secrets-vault-hygiene 2026-07-24 14:05:55 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!216
Ingen beskrivning angiven.