ops-warden/wiki/playbooks/policy-nexus-forgejo-source-read.md
tegwick 4fee839b11 feat: route Policy Nexus source credential
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:46:28 +02:00

2.3 KiB

Policy Nexus Forgejo source-read token

Date: 2026-09-01 Catalog: policy-nexus-forgejo-source-read (status active, resolvable: true) Owner: railiance-platform (OpenBao and credential lifecycle)

This lane carries the dedicated Forgejo PAT used by Policy Nexus Actions to fetch exact archives from private owner repositories. The Forgejo identity is restricted to organization-wide repository-code read and the PAT scope is exactly read:repository. It has no repository write, package, organization administration, instance administration, cluster, or deployment authority.

The authoritative lifecycle and evidence record is railiance-platform/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml. Warden is a governed conduit and never owns, persists, caches, or logs the PAT.

Owner-confirmed lane

Field Value
OpenBao path platform/workloads/policy-nexus/forgejo-source-read
Primary field FORGEJO_SOURCE_TOKEN
Read policy workload-kv-read-policy-nexus-forgejo-source
OIDC role policy-nexus-forgejo-source-workload-kv-read
Forgejo identity policy-nexus-source
Forgejo team policy-nexus-source-readers
Actions consumer coulomb/policy-nexus secret FORGEJO_SOURCE_TOKEN

Worker checklist

  1. Authenticate as an approved operator through the exact OIDC role. Do not substitute the Forgejo admin PAT or a broader OpenBao identity.

  2. Confirm the route before use:

    warden route show policy-nexus-forgejo-source-read --json | jq .resolvable
    

    The result must be true, and the rendered fetch must contain no placeholder.

  3. Agent callers must use a sanctioned high-risk transport. Pass the value only to the bounded source-consuming child:

    warden access policy-nexus-forgejo-source-read \
      --field FORGEJO_SOURCE_TOKEN --exec -- <reviewed-source-read-command>
    

    Do not use raw --fetch, place the value on argv, or write it to chat, Git, State Hub, workflow logs, or a persistent temporary file.

  4. For rotation or compromise, follow CCR-2026-0014. A replacement is not active until its scope and negative permissions are verified and one exact-commit Policy Nexus candidate workflow succeeds; revoke the predecessor afterward.