Commit Graph

4 Commits

Author SHA1 Message Date
MickLesk
7481db59e1 Rename CI credentials to org-wide names, demote non-secrets to variables
Four GitHub Apps were reachable under three different key suffixes
(_PRIVATE_KEY, _KEY_, _SECRET) and their ids sat half in secrets, half
in variables. Each app now reads <APP>_ID from variables and
<APP>_PRIVATE_KEY from secrets:

  vars.APP_ID / secrets.APP_PRIVATE_KEY   -> GHAPP_HEADERS_*
  secrets.APP_{ID,KEY}_APPROVE_AND_MERGE  -> GHAPP_MERGEBOT_*
  vars.PUSH_MAIN_APP_ID / secrets.PUSH_MAIN_APP_SECRET -> GHAPP_SYNC_*
  secrets.PB_BOT_APP_{ID,PRIVATE_KEY}     -> GHAPP_PBBOT_*

Values that are not credentials become variables, so a failing run shows
what it talked to instead of ***:

  secrets.POCKETBASE_URL        -> vars.POCKETBASE_URL
  secrets.POCKETBASE_COLLECTION -> vars.POCKETBASE_COLLECTION
  secrets.FRONTEND_URL          -> vars.FRONTEND_URL (also replaces vars.SITE_URL)

The frontend endpoints shared three secrets where two suffice. Cache
revalidation and screenshot import have the same blast radius and merge;
the advisory ingest keeps its own secret because it feeds the update
helper on user systems:

  REVALIDATE_SECRET, SCREENSHOT_IMPORT_SECRET -> FRONTEND_INGEST_SECRET
  BREAKING_CHANGE_INGEST_SECRET               -> FRONTEND_ADVISORY_SECRET

PAT_MICHEL ties infrastructure to one person and existed at both org and
repo level, so the repo copy silently shadowed the org one; it becomes
GH_CROSS_REPO_TOKEN.
2026-08-31 16:03:17 +02:00
Michel Roegl-Brunner
31328336f8 Dispatch Incus sync via push-app-to-main app
community-scripts-pr-app lacks contents:write (only pull_requests:write), so
repository_dispatch returned 403. Switch to the push-app-to-main app, which
has contents:write.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1R2A9UYwyL1FwcsADzSWU
2026-08-25 14:29:35 +02:00
Michel Roegl-Brunner
f4199627ef Use GitHub App token to dispatch Incus sync
PAT_AUTOMERGE returned 401; switch the dispatch to the repo's standard
GitHub App (vars.APP_ID / secrets.APP_PRIVATE_KEY) scoped to the Incus repo.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1R2A9UYwyL1FwcsADzSWU
2026-08-25 14:18:51 +02:00
Michel Roegl-Brunner
488e5a21c5 Add instant Incus sync trigger on ct/install changes
Fire a repository_dispatch (proxmoxve-scripts-changed) to
community-scripts/Incus whenever a ct/ or install/ script changes on main,
so the mirror tracks upstream within minutes instead of waiting for its
daily cron. The mirroring + bootstrap rewrite stays in the Incus repo as the
single source of truth.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1R2A9UYwyL1FwcsADzSWU
2026-08-25 14:11:04 +02:00