mirror of
https://scm.tikali.ai/tikali/applications/monky/monky-deployd.git
synced 2026-09-18 04:36:15 +00:00
feat(install): read-only deploy token for the private package registry (v0.1.2)
The GitLab project is private (its parent groups are private, so it cannot be made public): the v0.1.1 one-liner answered 401 anonymously. install.sh gains --token / MONKY_DEPLOYD_TOKEN and sends `DEPLOY-TOKEN: <token>` (a GitLab deploy token, scope read_package_registry only, revocable) on every registry download, the script itself included; the token goes through a 0600 curl -K file (never the command line, the log or an xtrace). The grant is taken via --bootstrap-file when the script is piped (stdin IS the script). Ansible: monky_deployd_download_token (vaulted) -> DEPLOY-TOKEN header, no_log. Docs explain why, the token's scope and the --source gitea alternative (split-horizon Gitea, cbs/iac#102). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
This commit is contained in:
@@ -1,6 +1,24 @@
|
||||
<!-- xlate:verbatim-fences -->
|
||||
# Changelog
|
||||
|
||||
## v0.1.2 — 2026-09-05
|
||||
|
||||
- **The GitLab project is private** (its parent groups are private, so it cannot be made public;
|
||||
found when the v0.1.1 one-liner returned 401 anonymously). `install.sh` gains `--token <deploy-token>`
|
||||
/ `MONKY_DEPLOYD_TOKEN`: every download from the generic package registry — the script itself
|
||||
included — sends `DEPLOY-TOKEN: <token>`, a read-only GitLab **deploy token** (scope
|
||||
`read_package_registry` only, revocable), seeded in OpenBao at `monky/monky-tenancy/deployd-download`
|
||||
(key `token`) and handed to the box by the monky-tenancy install kit. The token never reaches the
|
||||
command line, the log or an xtrace (curl `-K` config file, 0600, deleted after the download;
|
||||
`set +x` forced). The one-liner now fetches `install.sh` from the registry
|
||||
(`…/monky-deployd/<ver>/install.sh`) instead of `-/raw/main`, and takes the bootstrap grant via
|
||||
`--bootstrap-file` — with `curl … | bash -s --` stdin IS the script, so it is no longer read for
|
||||
the grant in that mode. `--source gitea` (no token) stays the off-estate alternative.
|
||||
- Ansible role: `monky_deployd_download_token` (vaulted) → `DEPLOY-TOKEN` header on both fetches,
|
||||
`no_log: true`.
|
||||
- README / OPERATIONS: why (private project; split-horizon Gitea, cbs/iac#102), token scope, revocation.
|
||||
No agent behaviour change.
|
||||
|
||||
## v0.1.1 — 2026-09-05
|
||||
|
||||
- `install.sh` / ansible role / README: the **primary download is the public GitLab project's generic
|
||||
|
||||
Reference in New Issue
Block a user