secrets-engine/catalog/example-build-test-token.yaml
tegwick f87f4e5e4d refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry
Gitea's "project/package/release" terms are overloaded, so the catalog now uses
the most explicit words:
- org  = coulomb (the Gitea organisation)
- repo = whynot-design (the Gitea repository/product) — not an org, not a scope
- npm scope @whynot and package @whynot/design are distinct from both

Changes:
- catalog schema: replace conflated `owner` with required `org` + `repo`; `owner`
  is now a derived `org/repo` slug property
- npm-config delivery is data-driven: registry + scope live in
  delivery_config.npm and are validated; engine no longer hardcodes a registry
- exec delivery writes `<scope>:registry=<url>` + scoped `:_authToken` for the
  configured Gitea registry (token still env-expanded, never written to disk)
- pilot lane points at https://gitea.coulomb.social/api/packages/coulomb/npm/,
  scope @whynot, KV path coulomb/whynot-design/npm/publish
- npm-publish-demo uses @whynot scope so dry-run resolves the Gitea registry
- docs: terminology table; routing owner shown as coulomb/whynot-design
- tests: org/repo required, npm-config validation, registry authkey mapping

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 12:44:55 +02:00

44 lines
1.1 KiB
YAML

# Example BUILD-stage lane. Demonstrates that build entries can be looser:
# generated test values are allowed and no production decision is required.
id: example-build-test-token
org: coulomb
repo: platform-ci
stage: build
description: >-
Throwaway generated credential for build-stage integration tests. May be
generated locally; must never be reused in test or prod.
mount: secret
path: build/example/test-token
fields:
- api_token
consumers:
- name: build-runner
auth: approle
claim: "role:build-runner"
purpose: "exercise build-stage integration tests"
delivery_modes:
- exec-env
- read-check
# Build stage permits bootstrap-only / generated values without a prod decision.
approval:
model: bootstrap-only
notes: "Build stage: generated test secret, no production decision required."
verification:
positive: "build-runner token can read the generated value"
negative: "prod consumers cannot read build paths"
rotation:
expectation: "regenerate per run"
ttl: "1h"
deactivation:
expectation: "delete on build teardown"
audit:
evidence: "actor, path, timestamp, result — no secret value"