tap-writer ExternalSecret: repoint tap-token to /forgejo/ci-release-token #240
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#240
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The tap-writer runner's ExternalSecret (
deploy/forgejo-runner-tap-writer.yml) referenced/forgejo/tap-bump-token, which was never provisioned, so the secret sat inSecretSyncedErrorand the runner could not start.A suitable token already exists:
/forgejo/ci-release-token(write:repository), minted out-of-band a few days ago. Repoint thetap-tokenremoteRef.keyto it rather than minting the redundant dedicated token from #195's provision script.Trade-off accepted:
ci-release-tokenis broader (write:repositoryto all repos) than #195's intended least-privilege tap-only token. Chosen for expedience; revisit if blast radius matters.Discovered while triaging the runner-tier outage (coilysiren/inbox#65).