fix(ci): provision FG_CI_TOKEN alongside FORGEGRAPH_TOKEN #605
Open
gmackie
wants to merge 1 commit from
fix/provision-fg-ci-token into main
pull from: fix/provision-fg-ci-token
merge into: gmackie:main
gmackie:main
gmackie:fix-worker-deploy-launchers
gmackie:fix-automerge-checks
gmackie:chore/agent-release-0.1.73
gmackie:fix/generated-wrangler-route-isolation
gmackie:fix/outbox-redirect-manual
gmackie:feat/kanbanger-notifications
gmackie:feat/node-access-production
gmackie:feat/changeset-lookup
gmackie:fix/trace-presence-countif
gmackie:chore/agent-0.1.72
gmackie:fix/dev-node-ci
gmackie:fix/canary-bulk-secrets
gmackie:chore/agent-0.1.71
gmackie:fix/heartbeat-maintenance
gmackie:fix/agent-poll-timeout
gmackie:fix/review-defects
gmackie:tf-validate-forgegraf
gmackie:feat/notify-endpoint
gmackie:fix/tunnel-provisioner-decrypt
gmackie:review/trueflight-workflows
gmackie:chore/agent-0.1.70
gmackie:fix/journal-keep-tail
gmackie:chore/agent-0.1.69
gmackie:fix/workspace-deps-build-if-present
gmackie:feat/google-services-file
gmackie:feat/contract-diff-pr
gmackie:feat/deploy-phase-slow-alert
gmackie:feat/forge-schedules
gmackie:ci/forge-artifact-token
gmackie:feat/forge-slo-ingest
gmackie:feat/slo-span-template-join
gmackie:feat/contract-from-routes
gmackie:feat/fleet-delivery-rollup
gmackie:fix/mobile-push-permission-once
gmackie:feat/forge-onboarding
gmackie:feat/mobile-delivery
gmackie:feat/operation-slo
gmackie:feat/deployment-phases
gmackie:feat/delivery-monitoring
gmackie:feat/delivery-run-web
gmackie:fix/snapshot-local-retention
gmackie:fix/auth-backend-unavailable
gmackie:registry-rename
gmackie:access-apps
gmackie:observability-rollout-evidence
gmackie:fix-beta-hyperdrive
gmackie:fix-github-workflow-lifecycle
gmackie:fix-ci-gate-all-pipelines
gmackie:agent-0.1.68
gmackie:fix-explicit-deploy-revision
gmackie:agent-telemetry-candidate
gmackie:otel-operation-context
gmackie:otel-agent-jsonc-release
gmackie:otel-agent-jsonc
gmackie:otel-production-rollout
gmackie:effect4-migration
gmackie:fix/trace-presence-consumer-auth-20260916
gmackie:feat/trace-availability-20260916
gmackie:docs/fg-pr-create-jj-branch
gmackie:feat/deep-task-traces-20260915
gmackie:infra/signoz-foundry-upgrade
gmackie:release/agent-0.1.66
gmackie:feat/deployed-binding-drift
gmackie:feat/contract-cli
gmackie:feat/contract-operations-tab
gmackie:ci/web-build-job
gmackie:fix/deploy-after-contract-package
gmackie:fix/nix-gcroot-live-services
gmackie:fix/corepack-deploy-prompt
gmackie:feat/alchemy-state-store
gmackie:docs/fleet-sweep-scope-correction
gmackie:feat/contract-ingest
gmackie:feat/kvwn-telemetry-endpoints
gmackie:feat/contract-package
gmackie:perf/worker-smart-placement
gmackie:perf/hyperdrive-prepared-statements
gmackie:perf/worker-request-db-pool
gmackie:perf/dashboard-query-overlap
gmackie:perf/homepage-worker-memory
gmackie:fix/dashboard-initial-data
gmackie:fix/dashboard-app-load-recovery
gmackie:feat/ci-runner-cockpit
gmackie:chore/release-cli-0.3.8
gmackie:fix/audit-secret-sync-cache
gmackie:fix/system-audit-20260906
gmackie:feat/ci-row-app-and-pr-first
gmackie:fix/runner-label-parsing
gmackie:fix/ci-recovery-lane-and-queue-visibility
gmackie:fix/mobile-face-id-purpose
gmackie:fix/ci-gate-asks-the-remote
gmackie:feat/mobile-pr-delivery
gmackie:fix/onebox-secret-parity
gmackie:docs/app-checkout-guidance
gmackie:docs/field-report-veritas-deploy
gmackie:feat/apple-sign-in
gmackie:fix/harden-worker-secret-sync
gmackie:diagnose/control-plane-router-bindings
gmackie:fix/control-plane-settings-form
gmackie:fix/control-plane-secret-inheritance
gmackie:fix/control-plane-safe-diagnostics
gmackie:fix/control-plane-complete-version
gmackie:fix/control-plane-recovery-lane
gmackie:fix/control-plane-atomic-bootstrap
gmackie:fix/control-plane-promotion-payload
gmackie:fix/control-plane-version-envelope
gmackie:fix/control-plane-secret-version-promotion
gmackie:fix/control-plane-auth-bootstrap-order
gmackie:fix/control-plane-token-bootstrap
gmackie:fix/deploy-capacity-protocol
gmackie:fix/default-branch-no-literal
gmackie:feat/desktop-release-lane
gmackie:feat/workspace-registry-token
gmackie:feat/deploy-registry-auth
gmackie:release/agent-0.1.63
gmackie:feat/deploy-registry-credential
gmackie:fix/agent-deploy-registry-auth
gmackie:fix/nix-npmrc-userconfig
gmackie:fix/nix-registry-npm-auth
gmackie:fix/no-dead-preview-routes
gmackie:chore/anti-slop-0.3.0
gmackie:fix/runreport-0-1-2
gmackie:fix/transpile-runreport
gmackie:perf/settled-alerts-index-lookup
gmackie:fix/npmrc-home-on-runners
gmackie:chore/relock-runreport-0-1-1
gmackie:fix/registry-npmrc-home
gmackie:fix/app-delete-all-33-fks
gmackie:fix/traffic-lifecycle-recovery
gmackie:fix/app-delete-complete-graph
gmackie:feat/cf-origin-rules
gmackie:feat/deploy-failure-cause
gmackie:fix/app-delete-cascade
gmackie:fix/reconcile-window-rotation
gmackie:chore/agent-0.1.62
gmackie:chore/anti-slop-0.2.0
gmackie:fix/release-agent-hermetic-go
gmackie:fix/route-entries-array-of-tables
gmackie:chore/agent-0.1.61
gmackie:feat/strip-managed-routes
gmackie:fix/apex-route-and-reconcile-claim
gmackie:feat/token-default-expiry
gmackie:fix/reconcile-stale-split
gmackie:feat/nightly-e2e-gate
gmackie:feat/cli-token-mint
gmackie:docs/workspace-build-fleet-plan
gmackie:fix/route-strip-prefix
gmackie:docs/route-update-dns-only-not-propagated
gmackie:fix/deploy-poll-machine-scope
gmackie:feat/onebox-hostname-reconcile
gmackie:chore/release-cli-0.3.5
gmackie:fix/secrets-superjson
gmackie:chore/agent-0.1.57
gmackie:feat/manifest-auto-enroll
gmackie:feat/preview-verification
gmackie:release/agent-0.1.56-main
gmackie:feat/check-events-v2
gmackie:fix/preview-destroy-fk
gmackie:fix/preview-destroy-fk-2
gmackie:fix/preview-hook-selfheal
gmackie:docs/ci-field-reports-20260824
gmackie:chore/agent-0.1.55
gmackie:fix/preview-immutable-source
gmackie:feat/pr-preview-environments
gmackie:docs/pr-preview-plan
gmackie:feat/pipeline-graph-services
gmackie:fix/edge-scope-routes-per-node
gmackie:fix/workers-domain-rebind
gmackie:fix/onebox-enable
gmackie:chore/agent-0.1.54
gmackie:fix/nixci-experimental-features
gmackie:feat/release-verification
gmackie:feat/one-box-traffic
gmackie:feat/worker-runtime-budgets
gmackie:feat/mise-toolchains
gmackie:feat/one-box-traffic-phase1
gmackie:feat/one-box-traffic-phase2
gmackie:feat/one-box-traffic-phase3
gmackie:feat/one-box-traffic-phase4
gmackie:feat/one-box-traffic-phase5
gmackie:feat/one-box-traffic-phase6
gmackie:feat/one-box-traffic-phase7b
gmackie:fix/opennext-pnpm-pin
gmackie:fix/ci-poll-delivery
gmackie:ops/beta-schema-bootstrap
gmackie:fix/migrate-data-snapshot-and-load-timeout
gmackie:fix/access-runner-provision-timeout
gmackie:feat/beta-access-ci-runners
gmackie:fix/deploy-pnpm-pin-chain
gmackie:chore/agent-0-1-51
gmackie:fix/ci-expose-runner
gmackie:fix/ci-sandbox-pinned-toolchain
gmackie:fix/ci-runner-attribution
gmackie:fix/hetzner-resolve-diagnostics
gmackie:fix/ci-oxlint-diagnostics
gmackie:fix/node-hard-reboot
gmackie:fix/ci-turbo-log-parsing
gmackie:feat/ci-incident-readout
gmackie:fix/migrate-data-numeric-real
gmackie:fix/agent-darwin-detection
gmackie:docs/r2-lifecycle-request
gmackie:fix/codemod-timestamp-ms
gmackie:feat/migrate-data-connstr
gmackie:fix/creator-oidc-trusted-client
gmackie:twulmuksvyqqqvtpprmxxozvnoormxzt
gmackie:oxwnmtzsmnutroqoqkrwpwvrrzuksrxm
gmackie:fg-forgejo-rotate
gmackie:bob/gma-404
gmackie:fix/host-sandbox-input-priority
gmackie:fix/archive-deployment-targets
gmackie:feat/creator-oidc-client-2
gmackie:feat/creator-oidc-client
gmackie:ops/rotate-hub-secret-20260812
gmackie:feat/pg-to-d1-codemod
gmackie:fix/fg-read-token-enforcement
gmackie:ops/forgejo-token-expired
gmackie:feat/agent-cf-worker-telemetry
gmackie:docs/agent-repo-create-scopes
gmackie:fix/public-overlay-partial-updates
gmackie:feat/publication-desk-controls
gmackie:fix/stack-sync-default-branch
gmackie:docs/bob-forgejo-token-revocation-ops-note
gmackie:feat/ci-failures
gmackie:fix/sso-login-graceful-error
gmackie:opskknztvsspuypuyststwxpwsxsotsn
gmackie:feat/byo-sso
gmackie:vxsnywpvyzwsuwlnmopqqywtoytvowuo
gmackie:fix/ci-hostnode-precedence
gmackie:ruvpwzskkqzmnwusszlonpqvtmzwwuoz
gmackie:fix/mobile-fresh-install-typecheck
gmackie:ztvvwwqyuxvnptyoluylkspkpovuuwup
gmackie:feat/entra-id-login
gmackie:wunmlolywuswnvzlozkzmysywoywynrp
gmackie:wip/mobile-auth-prebuild
gmackie:bob/GMA-47/gtm-forgegraph-success-metrics-north-star-and-meas
gmackie:bob/GMA-48/gtm-forgegraph-market-positioning-indie-devops-sel
gmackie:bob/GMA-52/gtm-forgegraph-open-source-community-contribution-
gmackie:bob/GMA-53/gtm-forgegraph-competitive-landscape-differentiati
gmackie:feat/jj-ryu-bridge-rebased
gmackie:fix/selfupdate-tmpfile-leak
gmackie:fix/bwrap-datadir-ownership
gmackie:fix/selfupdate-swap-live-binary
gmackie:chore/android-variant-icons
gmackie:docs/preflight-cli-guide
gmackie:fix/eas-preview-app-variant-env
gmackie:fix/scaffold-pnpm-node-version
gmackie:fix/agent-integrations-auth
gmackie:feat/app-glance
gmackie:fix/agent-fetch-forgejo-token-for-clone
gmackie:feat/cli-creds-deepen
gmackie:feat/cli-creds-verify
gmackie:feat/cli-creds
gmackie:feat/databases-list-metrics
gmackie:ci/job-timeouts
No reviewers
Labels
Clear labels
community
Community process, governance, contribution UX
docs
Documentation improvements
forgegraph:public-update
Publish approved PR lifecycle updates to the ForgeGraph public feed.
good first issue
Suitable for first-time contributors
help wanted
Extra attention is needed; maintainers welcome a PR
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!605
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/provision-fg-ci-token"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Bob CI run 1194 went red on a single check while every substantive job passed:
The publisher authenticated with
secrets.FG_CI_TOKEN, but provisioning onlyever wrote
FORGEGRAPH_TOKENandFORGEGRAPH_REPOSITORY_ID. The two drifted:provisioning kept refreshing the name the workflow does not read, while the
hand-set
FG_CI_TOKENaged out.verifyBearerTokenenforcesexpiresAtonfg_*tokens, so an aged deploy token is refused.Why fix it here rather than in each workflow
A scan of
*/.forgejo/workflowsacross the fleet found 27 repos whoseworkflows read
FG_CI_TOKEN. Sixteen had already been migrated by hand to${{ secrets.FORGEGRAPH_TOKEN }}. Ten were still on the stale name:None are failing yet, because their hand-set copies have not expired. They will.
Fixing that one workflow at a time is ten pull requests to write the same line,
and it leaves the trap in place for the next repo scaffolded from an older
template. Writing the token under both names fixes every one of them centrally,
on their next provision, with no workflow edits at all.
One token, two names
/api/fg/ci/reportaccepts any deploy-scoped token, so a workflow readingeither name authenticates as the same identity. The test asserts that
explicitly: three PUTs, and
FG_CI_TOKEN's body must equalFORGEGRAPH_TOKEN's. Minting twice would leave one unused and make the audittrail lie about which credential a run actually used.
Verification
provision-ci-secrets.test.tsandprovision-ci-access-unit.test.tspass(5 tests). The call-count assertion moved from 2 to 3 and now checks the two
token PUTs carry identical bodies.
FORGEGRAPH_TOKENand provisioning a fresh token turned run 1194's failingreport job into run 1195's passing one. This change removes the need for that
per-repo edit.
Scope note
The endpoint that accepts a deploy-scoped token is the CI report one. Routes
calling
verifyBearerToken(req)withoutallowMachineScopesstill rejectmachine tokens, so a workflow hitting those (ForgeGraph's own
ai-review, whichcalls
/api/fg/changesets) needsFG_API_TOKENrather than either of these.That workflow is separately broken and dormant: it has failed since 2026-07-01
inside
actions/checkoutwith "some refs were not updated", which is not acredential problem and is not addressed here.
🤖 Generated with Claude Code
Bob CI run 1194 went red on one check while every real job passed: ForgeGraph CI report rejected: HTTP 401 The publisher authenticated with secrets.FG_CI_TOKEN, but provisioning only ever wrote FORGEGRAPH_TOKEN and FORGEGRAPH_REPOSITORY_ID. The two drifted: provisioning kept refreshing the name the workflow does not read, while the hand-set FG_CI_TOKEN aged out. verifyBearerToken enforces expiresAt on fg_* tokens, so an aged deploy token is refused. A scan of the fleet found 27 repos whose workflows read FG_CI_TOKEN. Sixteen had already been migrated by hand to ${{ secrets.FORGEGRAPH_TOKEN }}; ten were still on the stale name -- appealkey, driftport, filmroom, ForgeGraph, hypemarker, latchflow, leetcode, metro-code, personalWebsite, test-dojo. None were failing yet, because their hand-set copies have not expired. They will. Fixing that one workflow at a time is ten pull requests to write the same line, and it leaves the trap in place for the next repo scaffolded from an older template. Writing the token under both names fixes every one of them centrally, on their next provision, with no workflow edits at all. It is one token, not two. /api/fg/ci/report accepts any deploy-scoped token, so a workflow reading either name authenticates as the same identity. The test asserts that explicitly: three PUTs, and FG_CI_TOKEN's body must equal FORGEGRAPH_TOKEN's. Minting twice would leave one unused and make the audit trail lie about which credential a run used. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>Preview environment is live: https://pr-605-forgegraph.forgegraf.com
Deployed
058f3cb0with the beta stage's environment. It redeploys on every push and is destroyed when this PR closes.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.