From df660a04ade3e833849407c7a8ec15d0e28b16fb Mon Sep 17 00:00:00 2001 From: Steven Welch Date: Sun, 20 Sep 2026 10:32:53 -0600 Subject: [PATCH 1/2] fix: add terraform-libvirt-domain as chart updater App key recipient Distribute the existing CHART_UPDATER_GITHUB_APP_PRIVATE_KEY Actions secret to terraform-libvirt-domain for module release automation and document the proposed consumer in the canonical App runbook: the required manual selected-repository App installation (explicit rollout gate until an owner confirms it), the scoped installation-token request, and the shared-private-key authority risk. No App permission change, no new App, and no Terraform-managed installation; the App stays manually owner-managed. --- docs/chart-updater-github-app.md | 26 ++++++++++++++++++++++++++ secrets.tf | 1 + 2 files changed, 27 insertions(+) diff --git a/docs/chart-updater-github-app.md b/docs/chart-updater-github-app.md index 8acf200..51d7fa9 100644 --- a/docs/chart-updater-github-app.md +++ b/docs/chart-updater-github-app.md @@ -26,6 +26,32 @@ old AWS Secrets Manager copy is legacy and unreferenced. It is not part of normal key rotation or recovery. Deleting that legacy copy requires a separate approved cleanup after the agreed rollback window. +### Proposed consumer: terraform-libvirt-domain module releases + +`makeitworkcloud/terraform-libvirt-domain` is a proposed additional consumer of +the same App for module release automation. Its release workflow mints an +installation token from the canonical Actions secret and App ID, requesting +`owner: makeitworkcloud`, `repositories: terraform-libvirt-domain`, Contents +write, and Pull requests write only. Two owner gates apply before rollout is +complete: + +- An organization owner must add the repository to the App's organization + installation using **Only select repositories**. That installation is not yet + confirmed; until an owner confirms it, the consumer workflow cannot mint a + token and the change must not be treated as rolled out. +- The reviewed plan/apply must distribute the existing Actions secret to the + new source repository by adding it to the chart updater secret's + `repositories` recipient list. This broadens private-key distribution and + follows the approval path above. + +The workflow's `repositories` input scopes only the installation token it +mints. It does not scope the shared private key: any repository holding the +Actions secret can request tokens for every repository selected in the App +installation, limited only by the App's existing Contents and Pull requests +permissions. This proposal adds a recipient and a token request only; it does +not change App permissions, create another App, or move the manually owned +installation into Terraform. + ## Ownership boundaries | Concern | Owner and source of truth | diff --git a/secrets.tf b/secrets.tf index 001eccc..d9cee5e 100644 --- a/secrets.tf +++ b/secrets.tf @@ -95,6 +95,7 @@ locals { repositories = [ "charts", "kustomize-cluster", + "terraform-libvirt-domain", "tfroot-aws", "tfroot-cloudflare", "tfroot-gcp", From 241c50926a69ea2b57e2a244f52a6eb2f53ecc69 Mon Sep 17 00:00:00 2001 From: Steven Welch Date: Sun, 20 Sep 2026 10:36:13 -0600 Subject: [PATCH 2/2] docs: correct proposed-consumer wording in the App runbook Frame the unmerged consumer workflow prospectively ("proposed release workflow will") and replace the not-installed assertion with verify-then-gate semantics: the installation scope is unverified, rollout stays blocked until an owner confirms it, and token minting will fail only if the repository is not selected. No other runbook content changes. --- docs/chart-updater-github-app.md | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/docs/chart-updater-github-app.md b/docs/chart-updater-github-app.md index 51d7fa9..4cf3eeb 100644 --- a/docs/chart-updater-github-app.md +++ b/docs/chart-updater-github-app.md @@ -29,16 +29,17 @@ approved cleanup after the agreed rollback window. ### Proposed consumer: terraform-libvirt-domain module releases `makeitworkcloud/terraform-libvirt-domain` is a proposed additional consumer of -the same App for module release automation. Its release workflow mints an -installation token from the canonical Actions secret and App ID, requesting -`owner: makeitworkcloud`, `repositories: terraform-libvirt-domain`, Contents -write, and Pull requests write only. Two owner gates apply before rollout is -complete: - -- An organization owner must add the repository to the App's organization - installation using **Only select repositories**. That installation is not yet - confirmed; until an owner confirms it, the consumer workflow cannot mint a - token and the change must not be treated as rolled out. +the same App for module release automation. Its proposed release workflow will +mint an installation token from the canonical Actions secret and App ID, +requesting `owner: makeitworkcloud`, `repositories: terraform-libvirt-domain`, +Contents write, and Pull requests write only. Two owner gates apply before +rollout is complete: + +- An organization owner must verify the App's organization installation and + ensure it selects the repository using **Only select repositories**. The + installation scope is currently unverified; rollout stays blocked until an + owner confirms it, and token minting will fail if the repository is not + selected. - The reviewed plan/apply must distribute the existing Actions secret to the new source repository by adding it to the chart updater secret's `repositories` recipient list. This broadens private-key distribution and