Restore brokered Forgejo access for read-only directors #1523

Merged
coilyco-ops merged 1 commit from issue-1521 into main 2026-07-23 05:40:33 +00:00
Member

Restores the Go-bootstrap broker lifecycle for read-only directors, keeping Forgejo credentials root-held while giving the dropped agent only the broker socket. It also refreshes broker credentials from SSM to avoid stale-token 401s.

  • Starts and verifies the group-readable broker socket with daemon logs kept off the TUI.
  • Removes FORGEJO_TOKEN from the dropped agent environment while preserving root reaper behavior.
  • Adds bootstrap, broker authorization/refresh, and doctrine coverage.

Tests: ward exec test; guarded commit hooks including golangci-lint passed.

closes #1521
ward.workflow: pull-request-and-merge

Restores the Go-bootstrap broker lifecycle for read-only directors, keeping Forgejo credentials root-held while giving the dropped agent only the broker socket. It also refreshes broker credentials from SSM to avoid stale-token 401s. - Starts and verifies the group-readable broker socket with daemon logs kept off the TUI. - Removes `FORGEJO_TOKEN` from the dropped agent environment while preserving root reaper behavior. - Adds bootstrap, broker authorization/refresh, and doctrine coverage. Tests: `ward exec test`; guarded commit hooks including golangci-lint passed. closes #1521 ward.workflow: pull-request-and-merge
fix(director): restore brokered Forgejo access
All checks were successful
test / test (pull_request) Successful in 50s
2f047ae3ff
Author
Member

WARDED_WORKFLOW: blocked 🛑

details

manual close/update snapshot at 2026-07-23T05:38:42Z is newer than the latest ward acknowledgement at 2026-07-23T05:24:29Z

This action is blocked until the feedback is visibly acknowledged.

— Codex, via ward agent

WARDED_WORKFLOW: blocked 🛑 <details><summary>details</summary> manual close/update snapshot at 2026-07-23T05:38:42Z is newer than the latest ward acknowledgement at 2026-07-23T05:24:29Z This action is blocked until the feedback is visibly acknowledged. </details> <!-- ward-agent-signature --> — Codex, via `ward agent`
Author
Member

Acknowledged the current PR snapshot: no human review comments are present. The in-container review gate was intentionally skipped because the temporary Ward default is pending brokered QA.

<!-- ward-agent-signature --> Acknowledged the current PR snapshot: no human review comments are present. The in-container review gate was intentionally skipped because the temporary Ward default is pending brokered QA.
Author
Member

WARDED_WORKFLOW: blocked 🛑

details

human comment by @coilyco-ops at 2026-07-23T05:39:54Z is newer than the latest ward acknowledgement at 2026-07-23T05:39:44Z

This action is blocked until the feedback is visibly acknowledged.

— Codex, via ward agent

WARDED_WORKFLOW: blocked 🛑 <details><summary>details</summary> human comment by @coilyco-ops at 2026-07-23T05:39:54Z is newer than the latest ward acknowledgement at 2026-07-23T05:39:44Z This action is blocked until the feedback is visibly acknowledged. </details> <!-- ward-agent-signature --> — Codex, via `ward agent`
Author
Member

WARDED_WORKFLOW: #1523

details

Acknowledged the PR snapshot: no human review comments are present. The in-container review gate was intentionally skipped because the temporary Ward default is pending brokered QA.

WARDED_WORKFLOW: https://forgejo.coilysiren.me/coilyco-flight-deck/ward/pulls/1523 <details><summary>details</summary> Acknowledged the PR snapshot: no human review comments are present. The in-container review gate was intentionally skipped because the temporary Ward default is pending brokered QA. </details> <!-- ward-agent-signature -->
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-flight-deck/ward!1523
No description provided.