Skip to content

v1.7.0 identity: GitHub App service credentials and event reconciliation #1088

Description

@jeffhuber

Part of #1096.

Goal

Give the Operator a narrowly authorized service identity and deterministic GitHub event reconciliation without relying on a shared personal PAT.

Scope

  • GitHub App installation-token support with least-privilege permission documentation.
  • Polling-first reconciliation with optional webhook acceleration; webhook delivery is never the sole source of truth.
  • Repository allowlist, event cursor/checkpointing, duplicate suppression, rate-limit backoff, and revocation behavior.
  • Read-only shadow posture and separately authorized active mutation posture.
  • Owner setup and rotation runbook.

Acceptance criteria

  • The shadow profile operates with read-only metadata permissions.
  • The active profile requests only the minimum issue/PR/check/contents permissions required by approved actions.
  • Duplicate, reordered, delayed, and missing webhook fixtures reconcile correctly through polling.
  • Installation revocation and token expiry stop mutations and surface one owner action.
  • No personal user token is required by the standard Operator deployment.

Code Mower delivery

One focused PR with mocked GitHub App flows, reconciliation fixtures, docs, and independent exact-head review. Live App provisioning remains an owner-controlled pilot step.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestparallel-okCan be implemented in parallel once shared contracts are stabletier:RCode Mower generated labelv1.7Code Mower v1.7 single-tenant Operator

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions