Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2.3 KiB
Policy Nexus Forgejo source-read token
Date: 2026-09-01
Catalog: policy-nexus-forgejo-source-read (status active, resolvable: true)
Owner: railiance-platform (OpenBao and credential lifecycle)
This lane carries the dedicated Forgejo PAT used by Policy Nexus Actions to
fetch exact archives from private owner repositories. The Forgejo identity is
restricted to organization-wide repository-code read and the PAT scope is
exactly read:repository. It has no repository write, package, organization
administration, instance administration, cluster, or deployment authority.
The authoritative lifecycle and evidence record is
railiance-platform/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml.
Warden is a governed conduit and never owns, persists, caches, or logs the PAT.
Owner-confirmed lane
| Field | Value |
|---|---|
| OpenBao path | platform/workloads/policy-nexus/forgejo-source-read |
| Primary field | FORGEJO_SOURCE_TOKEN |
| Read policy | workload-kv-read-policy-nexus-forgejo-source |
| OIDC role | policy-nexus-forgejo-source-workload-kv-read |
| Forgejo identity | policy-nexus-source |
| Forgejo team | policy-nexus-source-readers |
| Actions consumer | coulomb/policy-nexus secret FORGEJO_SOURCE_TOKEN |
Worker checklist
-
Authenticate as an approved operator through the exact OIDC role. Do not substitute the Forgejo admin PAT or a broader OpenBao identity.
-
Confirm the route before use:
warden route show policy-nexus-forgejo-source-read --json | jq .resolvableThe result must be
true, and the rendered fetch must contain no placeholder. -
Agent callers must use a sanctioned high-risk transport. Pass the value only to the bounded source-consuming child:
warden access policy-nexus-forgejo-source-read \ --field FORGEJO_SOURCE_TOKEN --exec -- <reviewed-source-read-command>Do not use raw
--fetch, place the value on argv, or write it to chat, Git, State Hub, workflow logs, or a persistent temporary file. -
For rotation or compromise, follow CCR-2026-0014. A replacement is not active until its scope and negative permissions are verified and one exact-commit Policy Nexus candidate workflow succeeds; revoke the predecessor afterward.