railiance-platform/workplans/archived/260905-RPF-WP-0007-forgejo-admin-pat-openbao-cutover.md
codex 9f83e426c7 Consolidate platform workplans and assess intent gaps
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 11:14:42 +02:00

4.7 KiB

id type title domain repo status owner topic_slug created updated related_repos state_hub_workstream_id
RPF-WP-0007 workplan Forgejo admin PAT OpenBao consumer cutover financials railiance-platform finished codex railiance 2026-07-25 2026-07-26
activity-core
ops-warden
f4fd52ba-4e84-52e7-a8d7-667b72d3cc1b

RPF-WP-0007 - Forgejo admin PAT OpenBao consumer cutover

Goal

Cut the Forgejo package-prune consumer over from workstation-local PAT handling to the approved OpenBao lane recorded in CCR-2026-0006.

The immediate trigger is the unread ops-warden coordination message from July 12, 2026 requesting that tools/cmd/forgejo-package-prune stop depending on /tmp/forgejo-tegwick-api-token as the steady-state fallback when FORGEJO_ADMIN_TOKEN is unset.

Boundaries

This workplan may:

  • update the Forgejo package-prune token resolution path
  • update package-prune runbooks and operator handoff docs
  • coordinate the consumer contract with the approved credential lane

It must not:

  • move platform secret-governance ownership out of railiance-platform
  • paste token values into Git, State Hub, chat, shell history, or logs
  • break the existing prune workflow before the replacement path is verified

T01 - Inventory current consumer and fallback paths

id: RPF-WP-0007-T01
status: done
priority: medium
state_hub_task_id: "3e8ee5f4-cdca-5803-8a15-86156faf5673"

Record where the current Forgejo admin PAT is consumed and documented, including:

  • scripts/forgejo_package_prune.py
  • tools/cmd/forgejo-package-prune
  • docs/forgejo-package-prune.md
  • any activity-core automation handoff that still assumes workstation file drops

Done when the remaining /tmp/forgejo-tegwick-api-token dependency surface is explicit.

2026-07-26: Confirmed the remaining legacy surface in scripts/forgejo_package_prune.py and docs/forgejo-package-prune.md; the approved lane reference already lived in CCR-2026-0006 and docs/workload-kv-access-lanes.md.

T02 - Implement the approved non-file fallback path

id: RPF-WP-0007-T02
status: done
priority: high
state_hub_task_id: "2684056f-39a9-503a-91df-36f287fe4654"

Change the package-prune consumer so that, when FORGEJO_TOKEN and FORGEJO_ADMIN_TOKEN are unset, it uses the approved OpenBao-backed access path rather than the workstation file as the steady-state fallback.

Done when the token loader prefers the approved lane and the old file drop is demoted to break-glass or removed if no longer needed.

2026-07-26: scripts/forgejo_package_prune.py now resolves platform/workloads/forgejo/forgejo-admin field API_TOKEN through bao kv get when FORGEJO_TOKEN and FORGEJO_ADMIN_TOKEN are unset. Explicit FORGEJO_TOKEN_FILE / FORGEJO_ADMIN_TOKEN_FILE remain supported as attended break-glass handoffs, and /tmp/forgejo-tegwick-api-token only works when FORGEJO_ALLOW_LEGACY_FILE_FALLBACK=1 is set.

T03 - Update operator guidance and lane references

id: RPF-WP-0007-T03
status: done
priority: medium
state_hub_task_id: "34ecd9c9-486f-5509-bb74-6836d3515100"

Refresh the operator docs so they align with CCR-2026-0006, the routing catalog, and the final consumer behavior.

Done when the package-prune runbook no longer presents the workstation file as the primary path.

2026-07-26: Updated docs/forgejo-package-prune.md so the primary operator path is warden plan + bao login against forgejo-admin-workload-kv-read; the retired /tmp drop is now documented as legacy unwind only, with explicit break-glass env/file overrides kept for attended sessions.

T04 - Verify prune workflow and close the inbox request

id: RPF-WP-0007-T04
status: done
priority: medium
state_hub_task_id: "90355dee-66dd-593f-9444-a42ff15f2398"

Blocked on T01-T03.

Verify the consumer cutover with a non-secret dry-run and close the originating coordination loop from ops-warden.

Done when the replacement path is verified and the old unread message has a clear repo-local follow-up trail.

2026-07-26: Added focused token-resolution coverage in tests/test_forgejo_package_prune.py for direct env, explicit file overrides, OpenBao fallback, legacy-file gating, and operator-facing failure text. This closes the ops-warden coordination loop triggered by message 5be8e500-ebf5-405b-9aec-c902353ae719; the repo-local follow-up trail is now in this workplan, the prune runbook, and the loader implementation.

Acceptance

  • forgejo-package-prune no longer defaults to /tmp/forgejo-tegwick-api-token
  • The steady-state fallback path reads the approved OpenBao lane from CCR-2026-0006
  • Operator docs present OpenBao / warden routing as the primary path
  • Repo-local tests cover the new token-resolution behavior without reading secret values