08 – Audit Forgejo Write Access Across Workload Hosts #239
Labels
No labels
area:authentication
area:flake-utilities
area:performance
area:tbd
host:chaos
host:electra
host:fleet
host:lyra
host:nova
host:vega
investigation
phase:cutover
phase:deploy
phase:mcp
phase:module
phase:packaging
phase:prep
phase:validation
priority:high
priority:medium
project:attic-postgres-lyra-rollout
project:auto-update-reliability
project:auto-update-remediation
project:declarative-purity-cleanup
project:external-review
project:fleet-boundary-cleanup
project:host-facts-refactor
project:lyra-nixos-deploy
project:lyra-service-stack-migration
project:nebula-mesh-network
project:nixos-build-deployment-pipeline
project:security-hardening
project:service-stack-migration
project:vega-sillytavern-cutover
project:wiki-rebuild
repo:numtide/flake-utils
repo:numtide/nix-auth
repo:numtide/nixos-passthru-cache
repo:numtide/nix-relay
service:auto-update
service:mem0
service:nix
service:sillytavern
service:slskd
service:synthseek
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
nimmo/nixos-config#239
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Audit Forgejo credentials on workload hosts and remove only write authority that is genuinely unnecessary. Vega remains an authorised NixOS configuration development and publishing host, so it must retain the ability to push when Electra is unavailable.
Dependencies
Blocked by #236 and informed by #238.
Requirements
Validation
Publish a host-by-host credential inventory and rationale, explicitly identifying Vega's retained push path. Prove Vega and Lyra receive and activate a new configuration through the remote workflow while supported updates and private inputs still work. Verify that any credential removed from another host is not needed by its documented role.
08 – Remove Forgejo Write Access from Workload Hoststo 08 – Audit Forgejo Write Access Across Workload Hostsnimmo referenced this issue2026-09-23 18:02:02 +01:00
nimmo referenced this issue2026-09-23 18:44:07 +01:00