--- id: RPF-WP-0007 type: workplan title: "Forgejo admin PAT OpenBao consumer cutover" domain: financials repo: railiance-platform status: finished owner: codex topic_slug: railiance created: "2026-07-25" updated: "2026-07-26" related_repos: - activity-core - ops-warden state_hub_workstream_id: "f4fd52ba-4e84-52e7-a8d7-667b72d3cc1b" --- # RPF-WP-0007 - Forgejo admin PAT OpenBao consumer cutover ## Goal Cut the Forgejo package-prune consumer over from workstation-local PAT handling to the approved OpenBao lane recorded in `CCR-2026-0006`. The immediate trigger is the unread `ops-warden` coordination message from July 12, 2026 requesting that `tools/cmd/forgejo-package-prune` stop depending on `/tmp/forgejo-tegwick-api-token` as the steady-state fallback when `FORGEJO_ADMIN_TOKEN` is unset. ## Boundaries This workplan may: - update the Forgejo package-prune token resolution path - update package-prune runbooks and operator handoff docs - coordinate the consumer contract with the approved credential lane It must not: - move platform secret-governance ownership out of `railiance-platform` - paste token values into Git, State Hub, chat, shell history, or logs - break the existing prune workflow before the replacement path is verified ## T01 - Inventory current consumer and fallback paths ```task id: RPF-WP-0007-T01 status: done priority: medium state_hub_task_id: "3e8ee5f4-cdca-5803-8a15-86156faf5673" ``` Record where the current Forgejo admin PAT is consumed and documented, including: - `scripts/forgejo_package_prune.py` - `tools/cmd/forgejo-package-prune` - `docs/forgejo-package-prune.md` - any activity-core automation handoff that still assumes workstation file drops Done when the remaining `/tmp/forgejo-tegwick-api-token` dependency surface is explicit. 2026-07-26: Confirmed the remaining legacy surface in `scripts/forgejo_package_prune.py` and `docs/forgejo-package-prune.md`; the approved lane reference already lived in `CCR-2026-0006` and `docs/workload-kv-access-lanes.md`. ## T02 - Implement the approved non-file fallback path ```task id: RPF-WP-0007-T02 status: done priority: high state_hub_task_id: "2684056f-39a9-503a-91df-36f287fe4654" ``` Change the package-prune consumer so that, when `FORGEJO_TOKEN` and `FORGEJO_ADMIN_TOKEN` are unset, it uses the approved OpenBao-backed access path rather than the workstation file as the steady-state fallback. Done when the token loader prefers the approved lane and the old file drop is demoted to break-glass or removed if no longer needed. 2026-07-26: `scripts/forgejo_package_prune.py` now resolves `platform/workloads/forgejo/forgejo-admin` field `API_TOKEN` through `bao kv get` when `FORGEJO_TOKEN` and `FORGEJO_ADMIN_TOKEN` are unset. Explicit `FORGEJO_TOKEN_FILE` / `FORGEJO_ADMIN_TOKEN_FILE` remain supported as attended break-glass handoffs, and `/tmp/forgejo-tegwick-api-token` only works when `FORGEJO_ALLOW_LEGACY_FILE_FALLBACK=1` is set. ## T03 - Update operator guidance and lane references ```task id: RPF-WP-0007-T03 status: done priority: medium state_hub_task_id: "34ecd9c9-486f-5509-bb74-6836d3515100" ``` Refresh the operator docs so they align with `CCR-2026-0006`, the routing catalog, and the final consumer behavior. Done when the package-prune runbook no longer presents the workstation file as the primary path. 2026-07-26: Updated `docs/forgejo-package-prune.md` so the primary operator path is `warden plan` + `bao login` against `forgejo-admin-workload-kv-read`; the retired `/tmp` drop is now documented as legacy unwind only, with explicit break-glass env/file overrides kept for attended sessions. ## T04 - Verify prune workflow and close the inbox request ```task id: RPF-WP-0007-T04 status: done priority: medium state_hub_task_id: "90355dee-66dd-593f-9444-a42ff15f2398" ``` Blocked on T01-T03. Verify the consumer cutover with a non-secret dry-run and close the originating coordination loop from `ops-warden`. Done when the replacement path is verified and the old unread message has a clear repo-local follow-up trail. 2026-07-26: Added focused token-resolution coverage in `tests/test_forgejo_package_prune.py` for direct env, explicit file overrides, OpenBao fallback, legacy-file gating, and operator-facing failure text. This closes the `ops-warden` coordination loop triggered by message `5be8e500-ebf5-405b-9aec-c902353ae719`; the repo-local follow-up trail is now in this workplan, the prune runbook, and the loader implementation. ## Acceptance - [x] `forgejo-package-prune` no longer defaults to `/tmp/forgejo-tegwick-api-token` - [x] The steady-state fallback path reads the approved OpenBao lane from `CCR-2026-0006` - [x] Operator docs present OpenBao / `warden` routing as the primary path - [x] Repo-local tests cover the new token-resolution behavior without reading secret values