Files
terraform-git/config/git.unkin.net/user/unkin-agent.yaml
T
unkinben 4953142200
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Add unkin-agent Gitea identity with write but no merge
Why: AI coding agents currently push and open PRs as Ben's own account
using Ben's token, so their work is unattributable and carries Ben's full
owner privileges. A dedicated least-privilege identity separates agent work
from Ben's and keeps merge a human decision.

How:
- add the unkin-agent bot user (non-admin, no org/repo creation, limited
  visibility); it authenticates via ephemeral vault-plugin-secrets-gitea
  tokens, not a stored password
- add the agents team granting Write on all unkin repositories, the minimum
  needed to push branches and open PRs; unkin-agent is its only member
- add merge_whitelist_teams Owners to every default-branch protection rule
  that lacked a merge whitelist, so Write no longer implies merge and only
  Owners (Ben) can merge across the estate
2026-08-08 22:37:52 +10:00

19 lines
956 B
YAML

# Shared identity used by Ben's AI coding agents to submit work (branches, pull
# requests, issues, comments) as a distinct, attributable, least-privilege
# account instead of Ben's own login. Auth is via ephemeral API tokens minted by
# the vault-plugin-secrets-gitea engine (gitea/creds/unkin-agent) -- no token or
# usable password lives in this repo's state beyond the generated placeholder.
#
# Write access comes from the "agents" team (team/agents.yaml); merge is blocked
# by branch protection (merge whitelist = Owners only), so the agent can open and
# comment on PRs/issues but never merge or approve.
email: unkin-agent@unkin.net
full_name: "Unkin Agent"
description: "shared identity for automated AI coding agents -- write, never merge"
# Conservative bot posture: not a site admin, cannot create orgs or repos,
# profile visible only to signed-in users.
visibility: limited
admin: false
allow_create_organization: false
max_repo_creation: 0