fd82876f5f
Add a data-driven 'user' config kind so Gitea accounts are declared as config/git.unkin.net/user/<name>.yaml, mirroring the existing repository and team kinds. Wire the yaml into a new modules/user submodule that creates a gitea_user (provider go-gitea/gitea 0.7.0, already pinned). The provider's user resource requires a password; generate a per-user random_password so nothing sensitive is hardcoded and only a placeholder lives in state (tokens come later from vault-plugin-secrets-gitea). Provision teabot's implementer and reviewer personality accounts with a conservative posture: not site admins, no org creation, no repo creation, limited profile visibility. Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
15 lines
686 B
YAML
15 lines
686 B
YAML
# teabot "implementer" personality account.
|
|
# Used by the teabot daemon (unkin/teabot) to open issues/PRs as a distinct
|
|
# identity so its work is attributable. Auth is via an API token issued
|
|
# out-of-band (vault-plugin-secrets-gitea / static KV) -- no token or usable
|
|
# password lives in this repo's state beyond the generated placeholder.
|
|
email: teabot-implementer@unkin.net
|
|
full_name: "Teabot Implementer"
|
|
description: "teabot implementer bot -- automated agent (unkin/teabot)"
|
|
# Conservative bot posture: not a site admin, cannot create orgs or repos,
|
|
# profile visible only to signed-in users.
|
|
visibility: limited
|
|
admin: false
|
|
allow_create_organization: false
|
|
max_repo_creation: 0
|