railiance-platform/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml
codex a6d47c51cc
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record Policy Nexus metadata apply and diagnose bootstrap
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:18:15 +02:00

160 lines
7.1 KiB
YAML

id: CCR-2026-0014
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Policy Nexus Forgejo private-source read token lane
status: applied
created: '2026-08-31'
updated: '2026-08-31'
requester:
agent: codex
reason: PNEX-WP-0004 makes scheduled Policy Nexus candidate builds fetch exact archives
from private owner repositories. Anonymous Forgejo API/archive reads return 404,
while the existing Forgejo admin PAT carries package, repository-write, and admin
authority that the publication workflow must not receive.
review:
required: true
required_approvers:
- platform-operator
- policy-nexus-owner
comments:
- at: '2026-08-31T20:51:17+00:00'
reviewer: platform operator and Policy Nexus owner (chat approval)
decision: approved
comment: 'Approved 2026-08-31: dedicated restricted Forgejo service identity;
PAT scope exactly read:repository; all-repository repo.code read team with all
non-code units disabled; no package, repository-write, organization-admin, instance-admin,
cluster, or deployment authority; attended secret custody plus positive and
negative verification required.'
- at: '2026-08-31T20:51:18+00:00'
reviewer: platform operator and Policy Nexus owner (chat approval)
decision: binding_confirmed
comment: Confirmed reuse of the net-kingdom-admins OIDC group binding with only
workload-kv-read-policy-nexus-forgejo-source attached and a 15-minute TTL.
target:
domain: infotech
tenant: coulomb
workload: policy-nexus-actions
environment: production
purpose: Hold a dedicated Forgejo PAT with read:repository only and deliver it as
the FORGEJO_SOURCE_TOKEN secret to the policy-nexus Actions workflow.
openbao:
mount: platform
kv_path: platform/workloads/policy-nexus/forgejo-source-read
fields:
- FORGEJO_SOURCE_TOKEN
- API_USER
- API_BASE_URL
- TOKEN_SCOPES
- GENERATED_AT
policy_name: workload-kv-read-policy-nexus-forgejo-source
policy_file: openbao/policies/workload-kv-read-policy-nexus-forgejo-source.hcl
auth:
method: oidc
mount: netkingdom
role: policy-nexus-forgejo-source-workload-kv-read
allowed_redirect_uris:
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
- http://localhost:8250/oidc/callback
- http://127.0.0.1:8250/oidc/callback
oidc_scopes:
- openid
- profile
- email
- groups
user_claim: sub
groups_claim: groups
bound_claims:
groups:
- net-kingdom-admins
bound_claims_confirmed: true
policies:
- workload-kv-read-policy-nexus-forgejo-source
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: policy-nexus-forgejo-source-read
selector: policy nexus Forgejo private source repository read token Actions
readiness: pending-review
resolvable: false
delivery:
surface: forgejo-actions-secret
bootstrap_command: warden access openbao-platform-admin-login --exec -- scripts/openbao-bootstrap-policy-nexus-source.sh
target: Repository Actions secret FORGEJO_SOURCE_TOKEN on coulomb/policy-nexus.
Delivery is attended and must not expose the value in command output, process
arguments, Git, State Hub, or workflow logs.
forgejo_identity: policy-nexus-source
forgejo_team: policy-nexus-source-readers
forgejo_team_contract: Restricted service user; organization team permission read,
includes_all_repositories true, can_create_org_repo false, repo.code read, every
non-code unit none. PAT scope exactly read:repository.
risk:
classification: high
notes:
- The PAT scope is exactly read:repository; no package, repository-write, organization-admin,
user-write, cluster, or deployment authority.
- REGISTRY_TOKEN remains a separate package-write credential and is never reused
for source acquisition.
- The workflow binds the authorization header to https://forgejo.coulomb.social
and refuses cross-origin forwarding.
- The existing Forgejo admin PAT is not an acceptable fallback.
verification:
positive:
- A scheduled or dispatched policy-nexus workflow resolves every declared private
repository revision and exact archive, then publishes a candidate.
- The token metadata reports read:repository and no broader scopes without printing
the token value.
negative:
- The PAT cannot create, update, or delete repository content.
- The PAT cannot write packages or administer users, organizations, hooks, runners,
Actions secrets, or the Forgejo instance.
- A default or unrelated OpenBao identity cannot read the KV data path.
- Removing FORGEJO_SOURCE_TOKEN makes the workflow fail before source fetch.
activation_conditions:
- Platform operator and Policy Nexus owner approve this CCR.
- A dedicated service identity and read:repository-only PAT are created in an attended
Forgejo session.
- The OpenBao policy/auth path and non-secret metadata are reviewed before apply.
- The PAT is transferred directly into OpenBao and the repository Actions secret
without logs, chat, Git, State Hub, or persistent temp files.
- Positive and negative scope tests and one workflow run are recorded.
evidence:
- at: '2026-08-31T21:03:08+00:00'
actor: codex attended operator
kind: delegated_metadata_apply
result: blocked
details:
- Approved metadata dry-run passed; two governed platform-admin OIDC attempts
failed closed before command handoff; Warden revoked any possible session; no
OpenBao mutation or secret provisioning occurred.
- at: '2026-08-31T21:26:07+00:00'
actor: codex attended operator
kind: attended_oidc_handoff
result: blocked
details:
- Canonical bootstrap command from railiance-platform commit 1b85a3e failed closed
before child handoff; Warden revoked any possible session. OpenBao is initialized/unsealed
and its public health endpoint returns 200; the KeyCape openbao-admin authorize
path returns 302. No Forgejo identity, PAT, OpenBao secret value, Actions secret,
or workflow run was created.
- at: '2026-08-31T22:15:50+00:00'
actor: attended operator via governed platform-admin lane
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as attended operator via governed platform-admin
lane using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-policy-nexus-forgejo-source'
- 'Auth role metadata write: auth/netkingdom/role/policy-nexus-forgejo-source-workload-kv-read'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Remove the repository Actions secret, revoke the Forgejo PAT, disable
the OpenBao access path, and leave scheduled publication failing closed.
rotate: Mint a replacement read:repository-only PAT, update OpenBao and the Actions
secret through attended custody, pass one candidate build, then revoke the predecessor.
compromised: Remove the Actions secret and revoke the PAT immediately, inspect private
repository read activity, rotate through the approved lane, and record a bounded
incident follow-up.
state_hub:
workplan_id: PNEX-WP-0004
task_id: PNEX-WP-0004-T03