docs: token inventory for #0015, resolve W5, sharpen W4
Inventoried the 24 git.lab PATs by metadata only — last_used_at separates 'needed' from 'lying around': four are in active use, five are active but never used at all (one with manage_runner and k8s scope), and several names exist twice because a replacement was created without revoking the old one. All six push mirrors are healthy, but GitLab masks both parts of the mirror URL, so the credential remains unidentifiable — and it is a Gitea token, which the PAT list cannot answer for. Hence the ordering: set a dedicated mirror credential first, revoke second. The revocations themselves are sorb's; from here a never-used token is indistinguishable from a staged one. W5 resolved: the secrets rule now has a bootstrap exception, since on a headless host it was only satisfiable by violating it. W4 splits — point 5 is #0015 (plus the WG key, which no token inventory covers), point 4 is demonstrably undone. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
f433fc2b2a
commit
463fb570d5
@@ -13,7 +13,7 @@ Verteilung: M1 6 · M2 18 · M4 2 · M5 4
|
||||
| [0008](docs/issues/0008-cfgmon-03-prometheus-remote-write-und-loki.md) | waiting | M1 | medium | CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung |
|
||||
| [0009](docs/issues/0009-cfgmon-04-grafana-admin-credentials-aus-env.md) | open | M2 | low | CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API |
|
||||
| [0014](docs/issues/0014-cfgmon-14-root-zugang-ueber-die-docker-gruppe.md) | open | M2 | low | CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur |
|
||||
| [0015](docs/issues/0015-cfgmon-15-token-hygiene-einmal-tokens-der.md) | next | M2 | medium | CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen |
|
||||
| [0015](docs/issues/0015-cfgmon-15-token-hygiene-einmal-tokens-der.md) | in-progress | M2 | medium | CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen |
|
||||
| [0018](docs/issues/0018-doc-01-wiki-rollout-abschliessen-ci-freigaben.md) | open | M2 | low | DOC-01: Wiki-Rollout abschließen — CI-Freigaben, Zeitplan, Dokploy-Stack, wiki.lab |
|
||||
| [0019](docs/issues/0019-doc-02-veralteten-wiki-branch-im-gitops-repo.md) | open | M2 | low | DOC-02: Veralteten `wiki`-Branch im gitops-Repo entfernen? |
|
||||
| [0021](docs/issues/0021-overmind-03-windows-build-vm-verschwindet-ci.md) | waiting | M2 | medium | OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen |
|
||||
|
||||
Reference in New Issue
Block a user