4953142200
Why: AI coding agents currently push and open PRs as Ben's own account using Ben's token, so their work is unattributable and carries Ben's full owner privileges. A dedicated least-privilege identity separates agent work from Ben's and keeps merge a human decision. How: - add the unkin-agent bot user (non-admin, no org/repo creation, limited visibility); it authenticates via ephemeral vault-plugin-secrets-gitea tokens, not a stored password - add the agents team granting Write on all unkin repositories, the minimum needed to push branches and open PRs; unkin-agent is its only member - add merge_whitelist_teams Owners to every default-branch protection rule that lacked a merge whitelist, so Write no longer implies merge and only Owners (Ben) can merge across the estate
18 lines
675 B
YAML
18 lines
675 B
YAML
description: "Private fork of OpenBao adding per-namespace raft, cross-cluster performance replicas, virtual KV, and KV events"
|
|
private: true
|
|
default_branch: "main"
|
|
default_delete_branch_after_merge: true
|
|
default_merge_style: "squash"
|
|
branch_protection:
|
|
- rule_name: "main"
|
|
merge_whitelist_teams:
|
|
- "Owners"
|
|
# Whitelist-push: the owner can push main directly (needed for the initial
|
|
# push and the fork's maintenance workflow); everyone else must open a PR.
|
|
enable_push: true
|
|
push_whitelist_users:
|
|
- "unkinben"
|
|
# PRs to main must pass the fork build/vet pipeline before merge.
|
|
status_check_contexts:
|
|
- "ci/woodpecker/pr/build"
|