77 lines
2.4 KiB
YAML
77 lines
2.4 KiB
YAML
# NON-SECRET catalog metadata derived from railiance-platform CCR-2026-0006.
|
|
id: forgejo-admin-api-token
|
|
kind: kv
|
|
org: coulomb
|
|
repo: railiance-platform
|
|
stage: prod
|
|
description: >-
|
|
Forgejo site-admin PAT and non-secret companion metadata for attended operator
|
|
and automation tooling. This lane is distinct from Forgejo SMTP credentials.
|
|
|
|
mount: platform
|
|
path: workloads/forgejo/forgejo-admin
|
|
mount_management: existing
|
|
fields:
|
|
- API_TOKEN
|
|
- API_USER
|
|
- API_BASE_URL
|
|
- TOKEN_SCOPES
|
|
- GENERATED_AT
|
|
|
|
consumers:
|
|
- name: forgejo-platform-operators
|
|
auth: oidc
|
|
claim: group:net-kingdom-admins
|
|
purpose: existing attended reads through forgejo-admin-workload-kv-read
|
|
- name: forgejo-automation
|
|
auth: approle
|
|
claim: catalog:forgejo-admin-api-token
|
|
purpose: approved package, repository, webhook, and bootstrap commands in a child process
|
|
|
|
workload_delivery:
|
|
- mode: operator-oidc
|
|
owner: railiance-platform
|
|
|
|
delivery_modes: [exec-env, read-check]
|
|
delivery_auth:
|
|
method: approle
|
|
management: engine
|
|
# Avoid broad-admin name guards while retaining an exact-path read policy.
|
|
policy_name: se-prod-forgejo-operator-api-token
|
|
role_name: se-prod-forgejo-operator-api-token
|
|
token_ttl: 15m
|
|
token_max_ttl: 30m
|
|
secret_id_ttl: 15m
|
|
secret_id_num_uses: 1
|
|
token_num_uses: 8
|
|
|
|
approval:
|
|
model: ccr
|
|
decision_ref: CCR-2026-0006
|
|
notes: >-
|
|
CCR-2026-0006 approves the existing OIDC/operator lane. A live native
|
|
AppRole apply remains gated by SECRETS-WP-0006-T05 review and operator approval.
|
|
|
|
verification:
|
|
positive: approved delivery AppRole can read declared fields and an exec smoke authenticates to Forgejo
|
|
negative: unrelated token is denied on platform/data/workloads/forgejo/forgejo-admin
|
|
|
|
risk:
|
|
classification: high
|
|
notes: API_TOKEN is a Forgejo site-admin PAT with package, repository, webhook, and operator impact
|
|
|
|
rotation:
|
|
owner: railiance-platform + Forgejo operator
|
|
expectation: >-
|
|
Mint a replacement PAT as the site-admin account, update OpenBao, verify all
|
|
consumers through exec delivery, then delete the old PAT in Forgejo.
|
|
ttl: provider-defined
|
|
|
|
deactivation:
|
|
owner: railiance-platform + Forgejo operator
|
|
expectation: >-
|
|
Disable the front door, detach native/OIDC read access, revoke the PAT in
|
|
Forgejo, and preserve package/webhook audit evidence.
|
|
|
|
audit:
|
|
evidence: CCR id, actor, exact path, field names, Forgejo token identifier/scopes if non-secret, timestamps, and pass/fail only
|