Skip to content

chore(secrets): re-seal token from FuzeInfra hand-off (fuzeagent-registration) - #163

Open
izzywdev wants to merge 5 commits into
mainfrom
handoff/fuzeagent-registration-2ad2dff4d1564d63
Open

chore(secrets): re-seal token from FuzeInfra hand-off (fuzeagent-registration)#163
izzywdev wants to merge 5 commits into
mainfrom
handoff/fuzeagent-registration-2ad2dff4d1564d63

Conversation

@izzywdev

Copy link
Copy Markdown
Owner

Automated credential hand-off from izzywdev/FuzeInfra (FuzeInfra#510).

  • Hand-off id: fuzeagent-registration
  • Target scope: fuzeagent/fuzefront-registration, key token (--scope strict)
  • Manifest: deploy/contabo/sealed/fuzefront-registration.yaml (updated with kubeseal --merge-into; all other keys untouched)
  • New credential fingerprint: 2ad2dff4d1564d63
  • Fingerprint currently deployed in fuzeagent: absent

This PR contains ciphertext only. It was produced without any human
or job log ever seeing the plaintext: FuzeInfra read its own Secret
in-cluster, sealed it against the controller cert, and published the
result. Merging it lets Argo CD sync the value into fuzeagent.

…stration)

Automated credential hand-off from izzywdev/FuzeInfra (FuzeInfra#510).

Only the encrypted `token` entry changed; every other key in this
SealedSecret is byte-identical (kubeseal --merge-into).

The value was sealed --scope strict for fuzeagent/fuzefront-registration, so this ciphertext
decrypts nowhere else. No plaintext was logged, committed, or handled
by a human at any point.

Credential fingerprint (sha256[:16]): 2ad2dff4d1564d63
Previously deployed fingerprint:      absent
@github-actions
github-actions Bot enabled auto-merge (squash) August 21, 2026 02:02
@claude claude Bot added the auto-merge Enable squash auto-merge once CI passes label Aug 21, 2026
fuzeone-bot and others added 2 commits September 1, 2026 21:59
This branch's head was pushed by an identity whose pushes do not trigger
workflows, so the PR had ZERO checks and could never satisfy branch
protection - nothing red to investigate, just nothing at all. A commit from
a collaborator-backed identity produces a synchronize event with a real
pusher, which is what actually starts CI.
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

fuze-code-review — automated verdict

No verdict was reached — this run is NOT an approval.

fuze-code-action conclusion was 'failure', not 'success' — no review was produced, so none can be approved. See the per-rung 'fuze-code-action' notices in the job log for the specific classification (availability / task / declined) and, on an availability failure, the named provider error that triggered it.

This is reported as a failed check deliberately: a review that could not run must never be silently indistinguishable from a clean one.

- name: Mint fuze-agent App installation token
id: app
if: inputs.app-id != '' && inputs.private-key != ''
uses: actions/create-github-app-token@v1
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

fuze-code-review — automated verdict

No verdict was reached — this run is NOT an approval.

fuze-code-action conclusion was 'failure', not 'success' — no review was produced, so none can be approved. See the per-rung 'fuze-code-action' notices in the job log for the specific classification (availability / task / declined) and, on an availability failure, the named provider error that triggered it.

This is reported as a failed check deliberately: a review that could not run must never be silently indistinguishable from a clean one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge Enable squash auto-merge once CI passes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants