Restore dev-base publisher registry authentication #685
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#685
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
Restore the AOS dev-base publisher by repairing the existing Forgejo
REGISTRY_TOKENlive credential path, then return one verified publication result.Evidence
Get "https://forgejo.coilysiren.me/v2/": unauthorizedfour times, then exits 1..forgejo/workflows/dev-base-publish.ymlsuppliessecrets.REGISTRY_TOKENto the shared publish action./forgejo/coilyco-ops/registry-tokenand the attendedward exec registry-token-provisionoperation. That operation verifieswrite:package, syncs the org Actions secret, and rotates only when explicitly passed--rotate.Ops verification
write:packageby running the committed infrastructureregistry-token-provisionoperation without rotation first.REGISTRY_TOKEN, and preserves the value entirely inside the established SSM and Forgejo flow.The engineer must not rerun Actions or mutate the live registry to probe this failure. This issue is the live handoff from agentic-os#781.
New live evidence from Galaxy Gen recovery:
registry-token-provision --rotatepath. The script stored the replacement in SSM and provedwrite:packagewith a real upload session.coilyco-flight-deckorg Actions secret. The prior org-secret value remains valid and was not revoked.Login Succeeded, pushed the immutable image, and passed remote manifest inspection.This proves the replacement credential and SSM path. Issue 685 still owns the attended org Actions-secret sync and one dev-base publication verification.