From f26cb6aca88bea7b0d63bb0e7350ef8a28dcff1d Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Thu, 20 Aug 2026 00:00:32 +1000 Subject: [PATCH] Remove ghp agent role (missing installation_id; unblock apply) The ghp agent role fails at apply with `installation_id is required for agent tokens` because config/ghp_secret_backend_role/ghp/agent.yaml carries a placeholder installation_id. Remove the role for now so the master apply goes green and does not block the arrstack #127 apply. The ghp backend is retained; re-add the role once a real installation_id is available. - Delete config/ghp_secret_backend_role/ghp/agent.yaml (empties the ghp_secret_backend_role for_each map). --- config/ghp_secret_backend_role/ghp/agent.yaml | 15 --------------- 1 file changed, 15 deletions(-) delete mode 100644 config/ghp_secret_backend_role/ghp/agent.yaml diff --git a/config/ghp_secret_backend_role/ghp/agent.yaml b/config/ghp_secret_backend_role/ghp/agent.yaml deleted file mode 100644 index b5653c7..0000000 --- a/config/ghp_secret_backend_role/ghp/agent.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints -# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds -# the minted token to a ghp App installation, so installation_id is REQUIRED. -# -# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App -# installation id before this role can mint usable tokens. scopes are ghp -# permission:level pairs; contents:read is the least-privilege default. ---- -token_type: agent -installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id -scopes: - - contents:read -session_prefix: vault -ttl: 3600 # 1h -max_ttl: 86400 # 24h