refactor(forgejo): point the service-account addresses at the noreply domain #416
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!416
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/rename-service-account-addresses"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ADR 0039, issues #390 and #393. The server was changed first; this makes the declaration match.
create-user.ymlis create-only and never reconciles an existing account's email, so editing these lines alone would not have changed the server — it would have drifted the declaration away from live state whilechanged=0kept reporting convergence.#390 — seven addresses
gitborg-*@gitborg.se→bitborg-*@noreply.git.bitborg.se, plusrenovate_git_author, the commit author on every Renovate PR and the most visible of the set.Forgejo's own noreply domain rather than the apex: none of these seven has a mailbox and none needs to receive, so
@bitborg.sewould have declared seven deliverable addresses that bounce. It's also the convention the org account already uses (bitborg@noreply.git.bitborg.se). Forgejo 16.0.1 accepts it as a user email — checked, not assumed.#393 — three website fields, not two
bitborghttps://www.gitborg.se/https://www.bitborg.se/bitborg-infrahttps://git.gitborg.se/https://git.bitborg.se/bitborg-webhttps://www.gitborg.se/https://www.bitborg.se/The issue listed the first two and flagged its own list as possibly incomplete —
bitborg-webwas a third. The other five repos, including all three private ones, have an emptywebsite, so nothing was hiding wherefj repo viewcan't show the field.No file changes for #393: it's pure server metadata, which is exactly why the repo-wide content sweeps never saw it.
⚠️
changed=0is NOT the evidence herecreate-user.ymlcannot reconcile an email, so it reports converged whatever these lines say. The assertion is against the API: all seven addresses and all three websites re-read with independent calls after the write, and every PAT survived — 10 tokens across the seven accounts, counts unchanged before and after (they key on the user id, not the login or the address).Done with a temporary credential, by necessity
No standing token can do this, deliberately: ADR 0024 keeps every admin token read-only (
webhook-adminandtoken-auditare both read:admin;vault_forgejo_admin_tokenwas removed). A short-lived write:admin PAT was minted, used, deleted locally and revoked. Never vaulted, so the least-privilege model is unchanged.Two API details cost a round trip, recorded so nobody repeats them:
PATCH /admin/users/{u}treatslogin_nameandsource_idas a pair — sendinglogin_namewith an email is a 422. Sendemailalone.GET /users/{u}/tokensneeds basic auth and 401s with a PAT. The working endpoint isGET /admin/users/{u}/tokens, the onetoken-auditalready uses. My first PAT-survival check used the wrong one and would have compared?to?and passed vacuously.LEGACY-PINcount invars.ymldrops 21 → 14.ansible-lint0/0 across 194 files atproduction.