Rename GITEA_ROTATION_TOKEN secret to ROTATION_PAT (GITEA_ prefix is reserved)

This commit is contained in:
2026-08-23 16:20:13 +02:00
parent 9424746305
commit 5b32539d65
2 changed files with 12 additions and 8 deletions
+7 -5
View File
@@ -8,9 +8,11 @@ name: Rotate Coder API Token
# it replaced. # it replaced.
# #
# One-time bootstrap (see README "Auto-provisioning" section): a # One-time bootstrap (see README "Auto-provisioning" section): a
# GITEA_ROTATION_TOKEN secret holding a Gitea personal access token # ROTATION_PAT secret holding a Gitea personal access token (write:repository
# (write:repository scope, no expiration) with permission to write this # scope, no expiration) with permission to write this repo's Actions secrets.
# repo's Actions secrets. Nothing else needs to touch this ever again. # Not named GITEA_ROTATION_TOKEN because Gitea reserves the GITEA_ prefix for
# its own automatic tokens/variables and rejects secrets with that prefix.
# Nothing else needs to touch this ever again.
on: on:
schedule: schedule:
@@ -23,7 +25,7 @@ jobs:
env: env:
CODER_URL: ${{ secrets.CODER_URL }} CODER_URL: ${{ secrets.CODER_URL }}
CODER_SESSION_TOKEN: ${{ secrets.CODER_SESSION_TOKEN }} CODER_SESSION_TOKEN: ${{ secrets.CODER_SESSION_TOKEN }}
GITEA_ROTATION_TOKEN: ${{ secrets.GITEA_ROTATION_TOKEN }} ROTATION_PAT: ${{ secrets.ROTATION_PAT }}
GITEA_API_URL: ${{ github.server_url }}/api/v1 GITEA_API_URL: ${{ github.server_url }}/api/v1
GITEA_REPO_PATH: ${{ github.repository }} GITEA_REPO_PATH: ${{ github.repository }}
steps: steps:
@@ -56,7 +58,7 @@ jobs:
BODY="$(jq -n --arg data "$NEW_TOKEN" '{data:$data}')" BODY="$(jq -n --arg data "$NEW_TOKEN" '{data:$data}')"
HTTP_STATUS="$(curl -s -o /tmp/put-secret.out -w '%{http_code}' \ HTTP_STATUS="$(curl -s -o /tmp/put-secret.out -w '%{http_code}' \
-X PUT \ -X PUT \
-H "Authorization: token ${GITEA_ROTATION_TOKEN}" \ -H "Authorization: token ${ROTATION_PAT}" \
-H "Content-Type: application/json" \ -H "Content-Type: application/json" \
-d "$BODY" \ -d "$BODY" \
"${GITEA_API_URL}/repos/${GITEA_REPO_PATH}/actions/secrets/CODER_SESSION_TOKEN")" "${GITEA_API_URL}/repos/${GITEA_REPO_PATH}/actions/secrets/CODER_SESSION_TOKEN")"
+5 -3
View File
@@ -201,12 +201,14 @@ workflow write to its own repo's secrets):
1. Create a Gitea personal access token with **write:repository** scope and 1. Create a Gitea personal access token with **write:repository** scope and
**no expiration** (Settings -> Applications -> Generate New Token). This **no expiration** (Settings -> Applications -> Generate New Token). This
one doesn't rotate itself, so give it a long life up front. one doesn't rotate itself, so give it a long life up front.
2. Add it as a repo/org Actions secret named `GITEA_ROTATION_TOKEN` (same 2. Add it as a repo/org Actions secret named `ROTATION_PAT` (same
Settings -> Actions -> Secrets page as above - if that tab is missing, Settings -> Actions -> Secrets page as above - if that tab is missing,
see the nav-link workaround / API fallback in the "Auto-provisioning" see the nav-link workaround / API fallback in the "Auto-provisioning"
section above, same `curl -X PUT .../actions/secrets/<name>` pattern, section above, same `curl -X PUT .../actions/secrets/<name>` pattern,
just with `GITEA_ROTATION_TOKEN` as the secret name and the PAT itself as just with `ROTATION_PAT` as the secret name and the PAT itself as the
the value). value). Not named `GITEA_ROTATION_TOKEN` - Gitea reserves the `GITEA_`
prefix for its own automatic tokens/variables and rejects secrets with
that prefix (`Error: invalid variable or secret name`).
After that, `CODER_SESSION_TOKEN` never needs manual attention again - you After that, `CODER_SESSION_TOKEN` never needs manual attention again - you
can also trigger a rotation on demand from Gitea's Actions tab can also trigger a rotation on demand from Gitea's Actions tab