Consolidate platform workplans and assess intent gaps
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
9d958f8e09
commit
9f83e426c7
40 changed files with 2985 additions and 295 deletions
|
|
@ -1,139 +0,0 @@
|
|||
---
|
||||
id: RPF-WP-0007
|
||||
type: workplan
|
||||
title: "Forgejo admin PAT OpenBao consumer cutover"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-07-25"
|
||||
updated: "2026-07-26"
|
||||
related_repos:
|
||||
- activity-core
|
||||
- ops-warden
|
||||
state_hub_workstream_id: "f4fd52ba-4e84-52e7-a8d7-667b72d3cc1b"
|
||||
---
|
||||
|
||||
# RPF-WP-0007 - Forgejo admin PAT OpenBao consumer cutover
|
||||
|
||||
## Goal
|
||||
|
||||
Cut the Forgejo package-prune consumer over from workstation-local PAT handling
|
||||
to the approved OpenBao lane recorded in `CCR-2026-0006`.
|
||||
|
||||
The immediate trigger is the unread `ops-warden` coordination message from
|
||||
July 12, 2026 requesting that `tools/cmd/forgejo-package-prune` stop depending
|
||||
on `/tmp/forgejo-tegwick-api-token` as the steady-state fallback when
|
||||
`FORGEJO_ADMIN_TOKEN` is unset.
|
||||
|
||||
## Boundaries
|
||||
|
||||
This workplan may:
|
||||
|
||||
- update the Forgejo package-prune token resolution path
|
||||
- update package-prune runbooks and operator handoff docs
|
||||
- coordinate the consumer contract with the approved credential lane
|
||||
|
||||
It must not:
|
||||
|
||||
- move platform secret-governance ownership out of `railiance-platform`
|
||||
- paste token values into Git, State Hub, chat, shell history, or logs
|
||||
- break the existing prune workflow before the replacement path is verified
|
||||
|
||||
## T01 - Inventory current consumer and fallback paths
|
||||
|
||||
```task
|
||||
id: RPF-WP-0007-T01
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "3e8ee5f4-cdca-5803-8a15-86156faf5673"
|
||||
```
|
||||
|
||||
Record where the current Forgejo admin PAT is consumed and documented, including:
|
||||
|
||||
- `scripts/forgejo_package_prune.py`
|
||||
- `tools/cmd/forgejo-package-prune`
|
||||
- `docs/forgejo-package-prune.md`
|
||||
- any activity-core automation handoff that still assumes workstation file drops
|
||||
|
||||
Done when the remaining `/tmp/forgejo-tegwick-api-token` dependency surface is explicit.
|
||||
|
||||
2026-07-26: Confirmed the remaining legacy surface in
|
||||
`scripts/forgejo_package_prune.py` and `docs/forgejo-package-prune.md`; the
|
||||
approved lane reference already lived in `CCR-2026-0006` and
|
||||
`docs/workload-kv-access-lanes.md`.
|
||||
|
||||
## T02 - Implement the approved non-file fallback path
|
||||
|
||||
```task
|
||||
id: RPF-WP-0007-T02
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "2684056f-39a9-503a-91df-36f287fe4654"
|
||||
```
|
||||
|
||||
Change the package-prune consumer so that, when `FORGEJO_TOKEN` and
|
||||
`FORGEJO_ADMIN_TOKEN` are unset, it uses the approved OpenBao-backed access
|
||||
path rather than the workstation file as the steady-state fallback.
|
||||
|
||||
Done when the token loader prefers the approved lane and the old file drop is
|
||||
demoted to break-glass or removed if no longer needed.
|
||||
|
||||
2026-07-26: `scripts/forgejo_package_prune.py` now resolves
|
||||
`platform/workloads/forgejo/forgejo-admin` field `API_TOKEN` through `bao kv get`
|
||||
when `FORGEJO_TOKEN` and `FORGEJO_ADMIN_TOKEN` are unset. Explicit
|
||||
`FORGEJO_TOKEN_FILE` / `FORGEJO_ADMIN_TOKEN_FILE` remain supported as attended
|
||||
break-glass handoffs, and `/tmp/forgejo-tegwick-api-token` only works when
|
||||
`FORGEJO_ALLOW_LEGACY_FILE_FALLBACK=1` is set.
|
||||
|
||||
## T03 - Update operator guidance and lane references
|
||||
|
||||
```task
|
||||
id: RPF-WP-0007-T03
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "34ecd9c9-486f-5509-bb74-6836d3515100"
|
||||
```
|
||||
|
||||
Refresh the operator docs so they align with `CCR-2026-0006`, the routing
|
||||
catalog, and the final consumer behavior.
|
||||
|
||||
Done when the package-prune runbook no longer presents the workstation file as
|
||||
the primary path.
|
||||
|
||||
2026-07-26: Updated `docs/forgejo-package-prune.md` so the primary operator path
|
||||
is `warden plan` + `bao login` against `forgejo-admin-workload-kv-read`; the
|
||||
retired `/tmp` drop is now documented as legacy unwind only, with explicit
|
||||
break-glass env/file overrides kept for attended sessions.
|
||||
|
||||
## T04 - Verify prune workflow and close the inbox request
|
||||
|
||||
```task
|
||||
id: RPF-WP-0007-T04
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "90355dee-66dd-593f-9444-a42ff15f2398"
|
||||
```
|
||||
|
||||
Blocked on T01-T03.
|
||||
|
||||
Verify the consumer cutover with a non-secret dry-run and close the originating
|
||||
coordination loop from `ops-warden`.
|
||||
|
||||
Done when the replacement path is verified and the old unread message has a
|
||||
clear repo-local follow-up trail.
|
||||
|
||||
2026-07-26: Added focused token-resolution coverage in
|
||||
`tests/test_forgejo_package_prune.py` for direct env, explicit file overrides,
|
||||
OpenBao fallback, legacy-file gating, and operator-facing failure text. This
|
||||
closes the `ops-warden` coordination loop triggered by message
|
||||
`5be8e500-ebf5-405b-9aec-c902353ae719`; the repo-local follow-up trail is now in
|
||||
this workplan, the prune runbook, and the loader implementation.
|
||||
|
||||
## Acceptance
|
||||
|
||||
- [x] `forgejo-package-prune` no longer defaults to `/tmp/forgejo-tegwick-api-token`
|
||||
- [x] The steady-state fallback path reads the approved OpenBao lane from `CCR-2026-0006`
|
||||
- [x] Operator docs present OpenBao / `warden` routing as the primary path
|
||||
- [x] Repo-local tests cover the new token-resolution behavior without reading secret values
|
||||
Loading…
Add table
Add a link
Reference in a new issue