Credential-less auth shim: authenticated HTTP request -> reconcile-trigger sentinel write (ADR 0037)
  • TypeScript 73.5%
  • JavaScript 17.8%
  • Dockerfile 8.7%
Hitta en fil
Kodförråd filer (senaste incheckning först)
Filnamn Senaste incheckningsmeddelande Senaste incheckningsdatum
Johannes Axner deba1c4c1d
Alla kontroller lyckades
ci / ci (push) Successful in 59s
docs(readme): state the release order, bump before tag (#50)
Docs only. The readme now states the release order: merge the version bump, verify `main` and `package.json`, then tag. A tag pushed before the bump merges builds the wrong commit.

Co-authored-by: Johannes <445378+supernaut@users.noreply.github.com>
Reviewed-on: #50
2026-10-02 22:19:05 +00:00
.forgejo/workflows ci: build the container image on every pull request (#49) 2026-10-01 19:49:50 +00:00
.vscode build: add vscode config 2026-07-29 01:15:34 +02:00
src feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
.env.example chore(rename): pin live identifiers to gitborg until the switchover 2026-08-03 11:24:50 +02:00
.gitignore feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
.markdownlint-cli2.jsonc fix: unbreak the ci format check and add lefthook hooks (#3) 2026-07-29 12:31:34 +00:00
.prettierignore feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
.prettierrc.json feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
Containerfile fix(image): copy pnpm-workspace.yaml into the build stage (#47) 2026-09-29 15:02:56 +00:00
eslint.config.mjs lint: type-checked eslint rules (#7) 2026-07-29 20:12:57 +00:00
lefthook.json chore(lefthook): run the full CI gate set on pre-push (#27) 2026-08-16 17:51:29 +00:00
LICENSE feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
package.json fix(image): copy pnpm-workspace.yaml into the build stage (#47) 2026-09-29 15:02:56 +00:00
pnpm-lock.yaml chore(deps): lock file maintenance (#45) 2026-09-29 08:30:48 +00:00
pnpm-workspace.yaml docs: stop naming private repositories (#42) 2026-09-24 13:03:33 +00:00
README.md docs(readme): state the release order, bump before tag (#50) 2026-10-02 22:19:05 +00:00
renovate.json chore(renovate): opt in to the shared automerge-safe preset (#22) 2026-08-09 19:55:21 +00:00
tsconfig.build.json feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
tsconfig.json feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00
vitest.config.ts feat: initial reconcile-trigger auth shim (ADR 0037 phase 2) 2026-07-29 00:49:54 +02:00

bitborg-reconcile-trigger

A tiny, credential-less auth shim that turns an authenticated HTTP request into a reconcile-trigger sentinel write for bitborg — the network ingress adapter of the event-driven reconcile trigger (ADR 0037).

What it does

The entitlement reconciler (ADR 0035) is a oneshot fired promptly by a systemd .path unit when a sentinel file appears. Co-located bitborg-web writes that sentinel directly. Callers that can only reach the host over HTTP — the Forgejo repository webhook (new repos) and the future payment service (cross-host) — go through this shim instead:

POST /  (Authorization: Bearer <token>)  →  validate → touch the sentinel → 204

That's the whole job. The shim:

  • holds no Forgejo or Kanidm credentials — a valid token can at most request a reconcile the 5-minute timer would run anyway, never dictate its outcome;
  • validates a per-source bearer token (constant-time), mapping it to a source label used only for logging;
  • fails closed — refuses to start without a sentinel path and at least one token.

It deliberately does not terminate TLS or do IP filtering: in production it runs as a container on the internal podman network (reached by name), with TLS + the firewall/allowlist handled at the edge (Caddy + nftables) by bitborg-infra.

Endpoints

Method Path Auth Response
GET /healthz none 200 (container health probe)
POST any Bearer 204 on valid token (sentinel written)
POST any bad/absent 401
other — — 405

Configuration

See .env.example: RECONCILE_SHIM_SENTINEL, RECONCILE_SHIM_TOKENS (source=token,…), RECONCILE_SHIM_PORT (default 8099).

Development

pnpm install
pnpm test         # vitest
pnpm lint         # eslint + prettier
pnpm typecheck
pnpm build        # → dist/
pnpm dev          # run from source

Deployed as a pinned container image (built + pushed by Forgejo Actions on a v* tag); consumed by bitborg-infra, with Renovate opening the bump PR — the same mechanics as the reconciler (ADR 0033 / ADR 0035). No :latest. Release order: merge the version bump, verify main and package.json, then tag. A tag pushed before the bump merges builds the wrong commit.

Licence

AGPL-3.0.