Skip to content

ci(oc): Refactor workflows to use GitHub app - #1626

Merged
EttyKitty merged 7 commits into
mainfrom
oc/app-setup
Oct 7, 2026
Merged

EttyKitty merged 7 commits into
mainfrom
oc/app-setup

Conversation

@EttyKitty

@EttyKitty EttyKitty commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by cubic

Tracks and replaces long-lived PAT secrets with short-lived GitHub App tokens minted per step in opencode.yml, opencode_issue_triage.yml, and opencode_review.yml, so each step only gets the permissions it needs. The bot identity now derives from the app slug instead of the hardcoded lyra-the-bot.

Refactors

  • Mints separate tokens for read-only admin checks, issues/PR interactions, and contents writes via actions/create-github-app-token.
  • Uses the write-scoped contents token only for the push step, keeping read access elsewhere.
  • Configures git committer as ${LYRA_SLUG}[bot] with the app user id from the gh api; the review trigger checks the requested reviewer via format('{0}[bot]', vars.LYRA_SLUG).
  • Requires LYRA_CLIENT_ID, LYRA_PRIVATE_KEY, and LYRA_SLUG to be set; PAT_ADMIN_READ, LYRA_CONTENTS_PRS_ISSUES_PAT, PAT_CONTENTS_WRITE, and LYRA_PRS_ISSUES_PAT are no longer used.

Written for commit 93de381. Summary will update on new commits.

View guided diff

Updated GitHub Actions workflow to use tokens generated by the create-github-app-token action for permissions on issues, pull requests, and contents.
@github-actions github-actions Bot added Type: CI Continuous Integration changes Size: Tiny labels Oct 7, 2026
@EttyKitty EttyKitty changed the title Refactor GitHub Actions to use app tokens for permissions ci(oc): Refactor /oc to use app tokens Oct 7, 2026
@EttyKitty

Copy link
Copy Markdown
Collaborator Author

/review

@lyra-the-bot lyra-the-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM directionally - replacing long-lived PATs with short-lived per-step App tokens is the right move, and the permission split is sound: administration:read only for the collaborator check, issues/prs:write + contents:read for comments/context, contents:write isolated to the push step. persist-credentials:false + explicit PUSH_TOKEN credential-helper handling is preserved (and safe - literal $PUSH_TOKEN in the helper, expanded at runtime, not baked into the config). Verify ops side before merge: vars.LYRA_APP_ID + secrets.LYRA_PRIVATE_KEY exist and the Lyra App is installed on this repo with administration(read), issues/pull-requests(write), contents(read/write) granted, otherwise all three mints fail. Minor nits inline.

Comment thread .github/workflows/opencode.yml Outdated
Comment thread .github/workflows/opencode.yml
Comment thread .github/workflows/opencode.yml Outdated
@EttyKitty EttyKitty changed the title ci(oc): Refactor /oc to use app tokens ci(oc): Refactor workflows to use app tokens Oct 7, 2026
@EttyKitty

Copy link
Copy Markdown
Collaborator Author

/review

@lyra-the-bot lyra-the-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Incremental changes since last review all check out: client-id replaces app-id for token minting (supported by create-github-app-token@v3), bot committer identity now derives from app-slug output with proper ID+name[bot]@users.noreply email instead of hardcoded lyra-the-bot, review trigger uses format('{0}[bot]', vars.LYRA_SLUG), and triage/review workflows fully drop LYRA_PRS_ISSUES_PAT in favor of per-job minted tokens. Contents-write token correctly narrowed to contents:write only and gated on opencode success. Verified no secrets.*PAT* references remain in workflows. Same ops precondition as before: vars.LYRA_CLIENT_ID / vars.LYRA_SLUG + secrets.LYRA_PRIVATE_KEY must exist and the app installed with administration(read), issues/PRs(write), contents(read/write).

@EttyKitty EttyKitty changed the title ci(oc): Refactor workflows to use app tokens ci(oc): Refactor workflows to use GitHub app Oct 7, 2026
@EttyKitty
EttyKitty merged commit 7201524 into main Oct 7, 2026
8 checks passed
@EttyKitty
EttyKitty deleted the oc/app-setup branch October 7, 2026 13:06
@EttyKitty EttyKitty linked an issue Oct 8, 2026 that may be closed by this pull request
2 of 12 tasks
@EttyKitty EttyKitty mentioned this pull request Oct 8, 2026
2 of 12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Size: Small Type: CI Continuous Integration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OpenCode Setup Improvments

2 participants