state-hub/api
tegwick 470ece82ed
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Multi-Context Image / build-and-push (push) Successful in 27s
feat(forge): resolve an optional forge read credential (STATE-WP-0084-T02/T03)
Nine repositories are invisible to derivation because central may not read
them. This adds the consuming half of the credential lane MASON-WP-0003 built.

The cluster has no agent injector and no secrets-store CSI driver, so the pod
authenticates to OpenBao with a projected ServiceAccount token (audience
`openbao`, not the API server) and reads the KV path itself. `forgeRead.*`
carries coordinates only; no credential is a chart value, an image layer, or a
Kubernetes Secret.

The credential reaches git through GIT_CONFIG_* setting http.extraHeader, not
through `-c` and not through userinfo in the clone URL — both of those put the
token in the process listing. It is redacted from ForgeDeriveError, which is
logged, stored in reset outcomes, and returned over the API.

Absent stays a supported state: with no credential, or with OpenBao
unreachable, resolution returns None and public derivation runs unchanged.
Raising would turn "nine repositories are unreadable" into "the pass failed",
which is what T01 exists to prevent.

Chart default is disabled. 717 pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-27 23:12:57 +02:00
..
edge feat(edge): add offline read cache for allowlisted State Hub GET routes 2026-07-09 01:04:15 +02:00
events chore: update standalone state hub wiring 2026-05-17 20:01:21 +02:00
models feat(tasks): give task rows a canonical record identifier 2026-08-26 02:05:51 +02:00
routers feat(deploy): run migrations as part of the release, and report schema state 2026-08-26 00:00:09 +02:00
schemas fix(classification): harden registration updates 2026-08-23 11:30:36 +02:00
services feat(forge): resolve an optional forge read credential (STATE-WP-0084-T02/T03) 2026-08-27 23:12:57 +02:00
classification.py fix(classification): allow the allowed-values path to be configured 2026-08-24 23:34:34 +02:00
config.py fix(config): bind the instance-identity settings to the env vars the chart sets 2026-08-25 12:55:11 +02:00
database.py Add state-hub v0.1 — local-first state service for the Custodian 2026-02-24 17:47:49 +01:00
doi_engine.py Production todo-md scan: sweep hostname + deploy tag main-d8808bf 2026-07-08 14:38:07 +02:00
flow_defs.py Complete workplan state model cleanup 2026-05-18 01:31:36 +02:00
main.py fix(retirement): close projection and launch contract gaps 2026-08-23 00:52:18 +02:00
task_status.py feat(tasks): adopt canonical task statuses 2026-05-26 01:32:50 +02:00
workplan_status.py feat(classification-spine): implement STATE-WP-0065 repo-anchored model 2026-06-22 13:52:13 +02:00