Keep release secrets in one environment behind secretless review gates - #751
Conversation
|
Five read-only reviews by Anthropic Acted on: top-level secret leak detection; derived approval counts/names; skipped/failure/cancelled gate dependencies; missing-gate fixtures; an owner-supported single-entry migration exception; safe activation/deletion documentation; live protection metadata checks before environment jobs; Deferred: historical original-commit reruns can bypass new gates after the old review role is removed; direction#24 owns that Director timing choice. The docs and owner hand step hold role removal/final activation until the choice is recorded on #747. Existing release secrets' actual placement remains unverified to this bot; #747's required names-only owner inventory and original-source single-entry exception own that acceptance. A missed signing name can still select the existing ad-hoc path when notarization is explicitly disabled; this is a real configuration risk, not disproved. The proposed blanket signing-presence restriction is not adopted because docs/release.md already supports ad-hoc publication and this task does not authorize retiring it. Preserve that limitation until the owner confirms the intended signing inventory/mode. Accounted-for residuals: the protection check is a snapshot, so an administrator can change settings afterward; the owner-only hand step waits for pending runs and unsets activation before such changes. Future computed environment names remain tracked in #750. The probe now makes narrower claims about the current secret-store fields; release guards verify the actual review gate. Whole-repository IDE analysis was not run because this change is limited to workflow/validation tooling; the configured narrow route is explicit PR files. Empty committed changed-file receipts were not counted. Exact-path inspections found and fixed two local shadow warnings, a default-argument warning and the mock target; the generated IDE environment received the script's declared PyYAML dependency. No inspection profile was weakened. No release was dispatched, and no environment or secret setting was changed. |
The setup in #748 duplicated credentials across environments and made rotations happen twice. This implements the recorded Owner decision: existing
releaseis the sole GitHub secret store, andrelease-approvalholds secretless review gates. Ship reviews once before its credentialed preflight and four channels; every standalone workflow retains its own gate. Only the exact protected-main Ship caller can skip a channel's second gate. No repository secrets are inherited by Ship's channel calls.Trust guards require owner-confirmed setup and read-only protection metadata before environment jobs. They verify the owner reviewer, disabled administrator bypass, solo self-review and the secret store's
main-only restriction. The CI probe verifies actual built-in-token access to the current protection fields and branch metadata. Reusable caller permissions are explicitly granted and linted. The owner hand step moves the reviewer role while leaving existing secret values untouched; a missing name has a supported single-entry move from its original private source. Chris's recorded Owner decision accepts the narrow historical-rerun exposure and says switch now, with no 30-day wait (context-panel#747 comment 5970898082). direction#24 is resolved; only Chris's manual environment setup and names/settings confirmation remain. No release or environment change is performed by this PR.Validation: full commit gate passed with 1,203 Swift tests, focused release suite 118 passed, final fast Python gate and policy fixtures passed, actionlint passed, and all-channel structural dry-run shows one Ship approval, one per standalone and one secret store. Exact 15-file PyCharm inspection GREEN with zero findings and lifecycle cleanup complete at current head 793093e; empty changed-file receipts were not counted. Four unchanged Markdown MD013 findings were reproduced on the base. Five Anthropic claude-opus-5-5 reviews were weighed; fixes and residual dispositions are recorded. The last review covered every approval implementation/workflow at 04ba9cf; final 793093e only clarifies docs and orders imports. Current-head CI's real metadata probe passed. Live approval prompts and owner secret-name inventory are still unverified and belong to the hand step/later authorized release. The optional ad-hoc signing mode remains; a missed signing inventory can still select it when notarization is disabled, so #747's owner inventory is required before activation.
The 822-line diff is one coherent role transition; the repeated seven-workflow guards and documentation replacement are mechanical, and the new policy/metadata behavior has fixture and independent review coverage.
Refs #747