Skip to content

Rotate agent-workloads workload identities#168

Open
cesaregarza wants to merge 1 commit into
mainfrom
codex/remint-workload-identities-now
Open

Rotate agent-workloads workload identities#168
cesaregarza wants to merge 1 commit into
mainfrom
codex/remint-workload-identities-now

Conversation

@cesaregarza

Copy link
Copy Markdown
Owner

Summary

  • re-mint the three agent-workloads workload identity tokens for the current main release pins
  • update workload-identity token metadata iat/exp and ciphertext checksum
  • leave image pins, values, runtime secrets, registry overlay, and DSNs untouched

Validation

  • SOPS_AGE_KEY_FILE=/root/dev/SplatTopConfig/keys/age-private.txt UV_CACHE_DIR=/root/dev/.uv-cache uv --directory /root/dev/SplatTopConfig-remint-now run python scripts/check_agent_workloads_identity_digests.py --repo-root /root/dev/SplatTopConfig-remint-now passed
  • PYTHONPATH=/root/dev/SplatTopConfig-remint-now UV_CACHE_DIR=/root/dev/.uv-cache uv --directory /root/dev/SplatTopConfig-remint-now run --python 3.13 --with pytest --with ruamel.yaml pytest tests/test_agent_workloads_identity_digests.py tests/test_agent_workloads_networkpolicy.py passed: 15 passed
  • git diff --check passed

Notes

  • Drift gate was already green before rotation; this PR is a token rotation against the same current sha-a1fb3e2c7a04 release digests.
  • Decrypt verification confirmed the token secret still contains exactly the three mwit_v1 workload identity keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant