Constrain Forgejo signups and runners before accepting untrusted accounts #658
Labels
No labels
burndown-2026-06
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#658
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
Permit external Forgejo accounts to open issues without letting those accounts create execution surfaces or select privileged runners.
Parent program: coilysiren/inbox#280
Current evidence
deploy/forgejo.ymlenables push-to-create for user and organization repositories.SCOPEis empty.deploy:host, mounts a deployer service-account token, and holds broad cluster mutation permissions.coilyco_ops_summon.pyauthorizes the summoning actor, but a trusted summon can still pass an externally authored issue body into Goose running as Kai with host credentials.Scope
Signup capabilities
Runner scope
Host-side summon boundary
Operational boundary
Runner re-registration, live Forgejo configuration changes, credential rotation, and live validation belong to Ops. Engineering authors and validates the canonical configuration from repository evidence. The rollout keeps old registrations available for rollback until scoped runners prove healthy.
Acceptance
Codex, via advisor surface
Engineering checkpoint landed on canonical main as
6f8beb3.Completed in the tracked state:
Live rollout and acceptance remain open under interactive Ops issue #664. That issue owns runner registration, SSM mutation, server apply, external-account denial checks, summon host verification, rollback evidence, and promotion of the proven resources into Flux. Keep #658 open until #664 returns that evidence.
Ops rollout #664 is at the final interactive wall.\n\nLanded and verified at 9c24a88:\n\n* Forgejo account-creation and fork restrictions are live while external-only registration remains enabled.\n* Seven organization- or repository-scoped runners are healthy under Flux.\n* Flight Deck, Bridge, Gaming, image-build, and deploy canaries passed. Tap-writer is visible only to homebrew-tap.\n* An unrelated user repository remains waiting with no eligible runner.\n* Every global registration was deleted, all legacy StatefulSets are 0/0, and the old SSM token was invalidated.\n* The repository gate, Flux readiness, and final infrastructure checks pass.\n* coilyco-gaming/sirens-discord-ops#43 tracks a workflow-specific failure found during canary testing. Another Gaming workflow passed on the same scoped runner.\n\nThe complete before-state and rollback evidence is on #664. Kai still needs to complete the sudo-backed summon installation and the real external OAuth account acceptance test. Keep this issue open until those two checks return.
Final verification found a host-installer defect after Kai completed the interactive checks. The tracked fix is on canonical main at
6e30cc3, and kai-server has the commit, but the sudo-installed unit files still need the installer rerun. The summon bot token family was also rotated after a verbose diagnostic disclosure, its consumers were refreshed, and the scoped deploy runner is Ready again. Detailed evidence is on #664. Keep this issue open until the corrected summon oneshot completes successfully.Acceptance is complete through Ops rollout #664. Forgejo external-account restrictions and scoped runners are live, every global runner registration is gone, trusted canaries passed, and Kai completed the external OAuth denial checks. The native
@coilyco-opshost-side Goose surface was retired entirely atdd9d903; live units, unit files, runtime state, and source are all absent. #664 holds the complete before-state, rollback, canary, credential-rotation, and final-retirement evidence.