Repository navigation
Keyless GCP token for BMC assimilation: WIF-federated scoped SA + GHA auth step (apply-ready) - #5676
Merged
Merged
Conversation
…tep (apply-ready) Make shell.GCloud.AuthPrintAccessToken() resolve on the self-hosted GitHub Actions runner with no pasted token. The .dag effect is unchanged; this is the host/CI config behind it plus the apply-ready GCP infra the operator runs. - extdeps/github/actions.dag: WorkflowPermissions.id_token + google_auth_action - workflow_yaml_project.dag: emit id-token permission - extdeps/cloud/gcp/iam.dag: ground roles/secretmanager.secretVersionAdder - gunbc/assimilate/bmc_token_federation.dag: identity facts, 2 resource-level secret bindings (single authority), WIF provider/principalSet, keyless auth step + smoke workflow emit - docs/runbooks/bmc-assimilator-wif-setup.md: exact apply-ready gcloud/WIF/GHA artifacts + scoped-key local fallback + least-privilege verification Least-privilege (one secret, two secretmanager roles, no project-wide) and keyless emission proven by execution in dsl/test/claim/bmc_token_federation_witness_test.dag (6 witnesses, all PASS). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…onstants + records Addresses review #5676 (claude-opus-4-7) single-authority findings: - bindings derive member (from sa_email), secret, project from the data constants via bmc_secret_binding() — no re-typed literals - role names sourced from iam.dag (role_secretmanager_secret_accessor / _version_adder), which common_roles now references too — one authority, and the new secretVersionAdder row gains a consumer - WIF resource-path + principalSet projection moved to reusable helpers in extdeps/cloud/gcp/gcp.dag (wif_provider_resource / wif_principal_set_for_repo), derived from the WifProvider/WifPool records; removed the ad-hoc concat ladders and duplicate scalar id/issuer data rows 7 witnesses still PASS; allowlist discriminating-red unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
extdeps.ctrl.jobserver (from #5663) declared its external-authority anchor as `ctrl_jobserver_authority`, but the host-fed clean-tree scanner (extdeps_shape_transport_policy_project::read_external_authority_anchor_from_items) requires the exact name `extdeps_external_authority_anchor` — so the module read as anchor-Absent and corpus_live_clean_tree_holds / extdeps_external_authority_gate have been RED on main since #5663, masked by the self-hosted runner CI backlog (main runs never completed). Surfaced on this PR's floor run. One-line rename to the convention every other extdeps module follows; anchor var was unreferenced. corpus_live_clean_tree_holds + corpus_live_anchored_modules_clean now PASS. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Make the
.dageffectshell.GCloud.AuthPrintAccessToken()resolve on the self-hosted GitHub Actions runner with no human pasting a token — the keyless path for unattended BMC assimilate jobs. Today a pasted ~1h token is the only path, which blocks any unattended assimilate job.The
.dageffect and its output wire are unchanged. Token acquisition is host/CI config behind the effect. The single token source staysshell.GCloud.AuthPrintAccessToken().access_token(the seam the interpreter consumer binds to — confirmed with @neat-boar-71). WIF only changes how gcloud is authenticated on the runner.What's here (apply-ready, NOT live-applied)
SA/WIF creation needs operator GCP-admin creds. This PR delivers the exact apply-ready artifacts + the in-substrate modeling:
extdeps/github/actions.dag—WorkflowPermissions.id_token+google_auth_action(google-github-actions/auth@v2).workflow_yaml_project.dag— emit theid-tokenpermission.extdeps/cloud/gcp/iam.dag— groundroles/secretmanager.secretVersionAdderincommon_roles(was missing; no nickname, DESIGN §3).gunbc/assimilate/bmc_token_federation.dag— single authority for the identity facts, the two resource-level secret bindings (accessor + versionAdder onbmc-srv3-adminonly), the WIF pool/provider/principalSet pinned togunb-ai/gunbc, the keyless auth step, and an emittable smoke workflow.docs/runbooks/bmc-assimilator-wif-setup.md— exact gcloud commands (SA, 2 resource-level grants, WIF pool+provider with repo attribute-condition, SA impersonation binding), the GHA auth step, a scoped-SA-key local fallback, and least-privilege verification commands.Least privilege
One secret (
bmc-srv3-admin), twosecretmanager.*roles, nothing project-wide, no admin. Blast radius = one secret.Proven by execution
dsl/test/claim/bmc_token_federation_witness_test.dag— 6 witnesses, all PASS:roles/secretmanager.*, one secret, one project, the SA memberid-token: write+ the authuses/with+gcloud auth print-access-tokencredentials_json/key (fail-closed against re-introducing a pasted key)ci.ymlverified byte-identical (id_tokenis Absent in the floor workflow → emits nothing).🤖 Generated with Claude Code