feat: wire the forge into the factory #1

Merged
beddari merged 1 commit from forge-and-vault into main 2026-09-17 11:36:40 +00:00
Owner

Outcome

The factory can drive git.dataverket.org as the operator: repositories, branch protection, tag protection, pull requests, Actions secrets, and runner registration, all through the forgejo swamp model with a scoped token read from a vault the factory can open unattended.

What changed

  • models/@thomas/forgejo/forgejo.yaml: the pulled community model, token via vault.get.
  • extensions/models/forgejo_actions.ts (+ tests): tag_protection_ensure, actions_secret_put (write-only), runner_registration_token (token stored in the vault, never in data).
  • vaults/forgejo.enc.json, .sops.yaml, vaults/@zocc/sops-age/: SOPS-encrypted secrets, recipients = factory age key + attester YubiKey.
  • README: step 1 of the next steps updated with what is done and what is left.

Already applied on the forge with this code: dataverket/fabrikk and dataverket/miljo created, main pull-request only, attestation/* pushable by beddari only.

Protected paths

Touches models/, extensions/, README.md. No factory run behind this PR: it is the change that makes the pull-request stage possible.

Test plan

  • ~/.swamp/deno/deno test --allow-all extensions/models/ (38 passing)
  • swamp model method run forgejo tag_protection_ensure ... twice: created, then unchanged
## Outcome The factory can drive git.dataverket.org as the operator: repositories, branch protection, tag protection, pull requests, Actions secrets, and runner registration, all through the `forgejo` swamp model with a scoped token read from a vault the factory can open unattended. ## What changed - `models/@thomas/forgejo/forgejo.yaml`: the pulled community model, token via `vault.get`. - `extensions/models/forgejo_actions.ts` (+ tests): `tag_protection_ensure`, `actions_secret_put` (write-only), `runner_registration_token` (token stored in the vault, never in data). - `vaults/forgejo.enc.json`, `.sops.yaml`, `vaults/@zocc/sops-age/`: SOPS-encrypted secrets, recipients = factory age key + attester YubiKey. - README: step 1 of the next steps updated with what is done and what is left. Already applied on the forge with this code: `dataverket/fabrikk` and `dataverket/miljo` created, `main` pull-request only, `attestation/*` pushable by `beddari` only. ## Protected paths Touches `models/`, `extensions/`, `README.md`. No factory run behind this PR: it is the change that makes the pull-request stage possible. ## Test plan - `~/.swamp/deno/deno test --allow-all extensions/models/` (38 passing) - `swamp model method run forgejo tag_protection_ensure ...` twice: created, then unchanged
Forgejo at git.dataverket.org, driven through swamp as the operator with a
scoped token: dataverket/fabrikk and dataverket/miljo exist, main is
pull-request only, and only the attester may push attestation/* tags.

- models/@thomas/forgejo: the pulled community model, token from the vault
- extensions/models/forgejo_actions.ts: adds tag_protection_ensure,
  actions_secret_put (write-only), and runner_registration_token (token to
  the vault) to @thomas/forgejo, with unit tests against a fake API
- vaults/forgejo.enc.json, .sops.yaml: secrets the factory reads unattended,
  SOPS-encrypted to the factory's age key and the attester's YubiKey; the
  @zocc/sops-age vault reads them with the factory key
- README: next steps updated with what is done and what is left in step 1
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!1
No description provided.