secrets-engine/catalog/forgejo-admin-api-token.yaml
tegwick 784be978bf
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
feat: admit existing OpenBao catalog lanes
2026-08-21 08:20:33 +02:00

77 lines
2.4 KiB
YAML

# NON-SECRET catalog metadata derived from railiance-platform CCR-2026-0006.
id: forgejo-admin-api-token
kind: kv
org: coulomb
repo: railiance-platform
stage: prod
description: >-
Forgejo site-admin PAT and non-secret companion metadata for attended operator
and automation tooling. This lane is distinct from Forgejo SMTP credentials.
mount: platform
path: workloads/forgejo/forgejo-admin
mount_management: existing
fields:
- API_TOKEN
- API_USER
- API_BASE_URL
- TOKEN_SCOPES
- GENERATED_AT
consumers:
- name: forgejo-platform-operators
auth: oidc
claim: group:net-kingdom-admins
purpose: existing attended reads through forgejo-admin-workload-kv-read
- name: forgejo-automation
auth: approle
claim: catalog:forgejo-admin-api-token
purpose: approved package, repository, webhook, and bootstrap commands in a child process
workload_delivery:
- mode: operator-oidc
owner: railiance-platform
delivery_modes: [exec-env, read-check]
delivery_auth:
method: approle
management: engine
# Avoid broad-admin name guards while retaining an exact-path read policy.
policy_name: se-prod-forgejo-operator-api-token
role_name: se-prod-forgejo-operator-api-token
token_ttl: 15m
token_max_ttl: 30m
secret_id_ttl: 15m
secret_id_num_uses: 1
token_num_uses: 8
approval:
model: ccr
decision_ref: CCR-2026-0006
notes: >-
CCR-2026-0006 approves the existing OIDC/operator lane. A live native
AppRole apply remains gated by SECRETS-WP-0006-T05 review and operator approval.
verification:
positive: approved delivery AppRole can read declared fields and an exec smoke authenticates to Forgejo
negative: unrelated token is denied on platform/data/workloads/forgejo/forgejo-admin
risk:
classification: high
notes: API_TOKEN is a Forgejo site-admin PAT with package, repository, webhook, and operator impact
rotation:
owner: railiance-platform + Forgejo operator
expectation: >-
Mint a replacement PAT as the site-admin account, update OpenBao, verify all
consumers through exec delivery, then delete the old PAT in Forgejo.
ttl: provider-defined
deactivation:
owner: railiance-platform + Forgejo operator
expectation: >-
Disable the front door, detach native/OIDC read access, revoke the PAT in
Forgejo, and preserve package/webhook audit evidence.
audit:
evidence: CCR id, actor, exact path, field names, Forgejo token identifier/scopes if non-secret, timestamps, and pass/fail only