hackforla / hackforla/devops

Move the danielridgebot workflows off secrets.DR_PAT onto the org GitHub App

Abierto
#223 0 comentarios 0 reacciones 0 asignados Ver en GitHub
complexity: medium feature: security role: DevOps Engineer size: 3pt
Lenguaje dominante
PowerShell
Estrellas
8
Forks
10
Merge medio
7 h 30 min
PR fusionados (30 d)
22

Descripción

### Overview

We need the danielridgebot workflows to create issues with a token minted from the org's GitHub App instead of `secrets.DR_PAT`, because that PAT is a personal access token on a recurring expiry cycle with nothing warning us when it lapses. Its failure mode is silence — a missed GitHub Pages version bump rather than an alert — so we would not find out until someone noticed the bot had gone quiet.

### Action Items

- [ ] Confirm first that the `HFLA_WORKFLOW_APP_*` App is installed on `hackforla/devops` with **Issues: write**, and that it has organization **Projects: write**. The bot creates its issues on `hackforla/devops` and adds them to board 73, so an installation scoped only to the bot repo is not enough. If the App cannot write to projects, that is the finding — record it on this issue rather than shipping something that silently stops adding board cards.
- [ ] In `check-gh-pages-version.yml` and `check-ruby-version.yml`, mint a token with `actions/create-github-app-token` from `secrets.HFLA_WORKFLOW_APP_ID` / `secrets.HFLA_WORKFLOW_APP_PRIVATE_KEY` and pass it as `GH_TOKEN` to the "Create issue…" step, in place of `secrets.DR_PAT`. Both org secrets are already readable by this repo — verified 2026-09-07.
- [ ] Leave the `git push` steps alone. They commit the new version file using the checkout-persisted `GITHUB_TOKEN`, not `DR_PAT`, so they are unaffected by this change.
- [ ] Decide what happens to `test-issue-labels.yml`, the third and last user of `DR_PAT`: switch it too, or delete it. It is `workflow_dispatch`-only, it opens issues on the bot repo itself, and the one it left behind — [check-ghpages-versions#22](https://github.com/hackforla/check-ghpages-versions/issues/22), open since May 2024 — is that repo's only open issue, so nothing sweeps what it creates.
- [ ] Test before relying on it. On a throwaway branch, set `release-versions/github-pages-gem.txt` to an older value and run `gh workflow run check-gh-pages-version.yml --ref `. The workflow commits the real version back, so the file self-restores — but it opens a **real issue on `hackforla/devops`** with a board card, so close that issue and delete its card afterwards.
- [ ] Check the test issue carries its labels, its milestone **and** a card on board 73. The board card is both the most likely thing to fail and the one that fails quietly.
- [ ] Once both check workflows are confirmed working on App tokens, delete the `DR_PAT` repo secret. Decide separately what happens to the `danielridgebot` user account itself — with the PAT retired it has no remaining job.
- [ ] Note that the issue **author** changes from `danielridgebot` to the App's bot identity. Nothing we know of filters on the author, but the weekly label check and anyone reading the board will see a different name — confirm that is acceptable before merging rather than after.

### Resources/Instructions

- The change is a PR on [hackforla/check-ghpages-versions](https://github.com/hackforla/check-ghpages-versions). This issue lives on `devops` because that is where the bot's issues land, where it is documented, and because the bot repo is not on board 73 and has almost no label vocabulary of its own.
- The bot's documentation: [@danielridgebot-DevOps-Wiki](https://github.com/hackforla/devops/wiki/@danielridgebot-DevOps-Wiki)
- `DR_PAT` was last rotated 2025-10-26 and confirmed working 2026-08-24, so it is currently valid. This is not urgent — it removes a recurring liability rather than fixing an outage.
- Org secrets already visible to the bot repo, verified 2026-09-07: `HFLA_WORKFLOW_APP_ID`, `HFLA_WORKFLOW_APP_PRIVATE_KEY`, `HFLA_GRAPHQL_APP_ID`, `HFLA_GRAPHQL_APP_PRIVATE_KEY`.
- **Do not "fix" the issue templates' frontmatter while you are in there.** `update-gh-pages-version.md` and `update-ruby-version.md` carry `projects:` as a board *title* and `milestones:` plural. GitHub never renders these files — the bot's own parser, `github-actions/utils/parse-issue-template.js`, reads the frontmatter and feeds it to `gh issue create --project "$PROJECTS"`, where a board title is exactly what is wanted. Changing them to `hackforla/73` would break the bot.
- **Do not delete `keepalive.yml`.** It looks like dead code and is load-bearing: GitHub disables scheduled workflows after 60 days with no repository commits, which is what silently killed both checks between 2026-01-07 and 2026-08-24. It is hand-rolled because the action the wiki recommends for this has been blocked by GitHub since 2025-04-21.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start with check-gh-pages-version.yml, check-ruby-version.yml, and test-issue-labels.yml in hackforla/check-ghpages-versions; review the existing DR_PAT usage and the create-github-app-token action. Test from a throwaway branch with gh workflow run check-gh-pages-version.yml --ref , then verify labels, milestone, and board 73 before cleaning up the test issue and card. Done means both checks work with the App token and the DR_PAT decision is recorded.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github, github-actions
Área
ci-cd, devops, security
Tipo de issue
Nueva funcionalidad
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Activo
Claridad
Bastante claro
Aptitud para principiantes
48/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.