Remove ghp agent role (missing installation_id; unblock apply)
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

The ghp agent role fails at apply with `installation_id is required for
agent tokens` because config/ghp_secret_backend_role/ghp/agent.yaml carries a
placeholder installation_id. Remove the role for now so the master apply goes
green and does not block the arrstack #127 apply. The ghp backend is retained;
re-add the role once a real installation_id is available.

- Delete config/ghp_secret_backend_role/ghp/agent.yaml (empties the
  ghp_secret_backend_role for_each map).
This commit is contained in:
unkin-agent
2026-08-20 00:00:32 +10:00
parent 392c5d2ac7
commit f26cb6aca8
@@ -1,15 +0,0 @@
# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints
# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds
# the minted token to a ghp App installation, so installation_id is REQUIRED.
#
# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App
# installation id before this role can mint usable tokens. scopes are ghp
# permission:level pairs; contents:read is the least-privilege default.
---
token_type: agent
installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id
scopes:
- contents:read
session_prefix: vault
ttl: 3600 # 1h
max_ttl: 86400 # 24h