feat(deploy): carry the registry credential in the deployment payload #514
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!514
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/deploy-registry-credential"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Removes the hand-set node config that #513 depends on.
#513 made the registry build able to authenticate, but the credential's only source was
FG_NPM_TOKENwritten by hand into/etc/forgegraph/agent.envon hetzner-fg. That is invisible, unreproducible, and silently absent on every other node — the next node to build the registry would fail exactly as this one did, with no indication why.CI already solved this.
fetchQueuedCIJobsattaches a resolved registry config per repository viaresolveCIRegistryForRepository. Deployments resolve the samerepositoryIda few lines earlier in the poll route, so this reuses the same helper and carries the result in the payload.registryPendingDeployment.Registry, matching the fieldCIJobalready hasbuildEnvexportsFG_NPM_TOKENfornix build, mirroring howgitauthsupplies git credentials. Environment rather than argv for the same stated reason: argv is world-readable through/proc.Absent a configured registry the token is empty and
buildEnvreturns nil, so nix inherits the parent environment exactly as before — public flakes are untouched.Tests — 4 new Go tests on the env assembly: the token is carried, the parent environment is preserved when materialised, a git credential and an npm token coexist (the case that would break if either clobbered the other), and an empty token is never exported.
go build/vetclean, existinginternal/deployandcmd/agentsuites pass,turbo run typecheck7/7, poll-route tests 9/9.Ships with the next agent release. Once it is out, the hand-set
FG_NPM_TOKENin/etc/forgegraph/agent.envcan be removed — I have left it in place so the registry keeps deploying in the meantime.🤖 Generated with Claude Code