Deprovision the unused tap-writer Forgejo runner #573
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#573
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The dedicated
tap-writerForgejo Actions lane is no longer used. Ward now bumps the Homebrew tap from its ordinaryruns-on: dockerrelease job with the explicitTAP_WRITE_TOKENsecret. A workspace-wide search found noruns-on: tap-writerconsumer.Acceptance criteria:
deploy/forgejo-runner-tap-writer.ymlandscripts/provision-tap-bump-token.sh.forgejo-runner-tap-writerStatefulSet, its ExternalSecret and generated Secret, and the retaineddata-forgejo-runner-tap-writer-0PVC.tap-bumpForgejo PAT and delete/forgejo/tap-bump-tokenfrom SSM without exposing its value.tap-writerlabel and the normal ward release tap bump remains green.pre-commit run --all-files, commit withcloses #<issue>, and push canonical main.Live Kubernetes, Forgejo admin, and SSM deletion steps require an attended operator-capable run.