Skip to content

ci(notify-front-desk): grant id-token: write — brokered cross-repo sync (prx-26bq)#19

Merged
bdelanghe merged 1 commit into
mainfrom
ci/notify-front-desk-oidc
Jun 29, 2026
Merged

ci(notify-front-desk): grant id-token: write — brokered cross-repo sync (prx-26bq)#19
bdelanghe merged 1 commit into
mainfrom
ci/notify-front-desk-oidc

Conversation

@bdelanghe

Copy link
Copy Markdown
Contributor

Grants permissions: id-token: write so the OIDC→cf-token-broker mint propagates through notify-front-desk → trigger-sync → front-desk-sync. Restores immediate cross-repo Front Desk sync without secrets. Verified via the site pilot (bounded-systems/site#95).

🤖 Generated with Claude Code

…s-repo sync (prx-26bq)

The front-desk sweep mints via the cf-token-broker over OIDC (no secrets).
Grant id-token: write on the calling job so it propagates through the
reusable chain (notify-front-desk → trigger-sync → front-desk-sync); drop
the now-useless secrets: inherit (FRONT_DESK_APP_* deleted). Verified via
the site pilot (bounded-systems/site#95).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@bdelanghe bdelanghe merged commit 592b130 into main Jun 29, 2026
4 checks passed
@bdelanghe bdelanghe deleted the ci/notify-front-desk-oidc branch June 29, 2026 03:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant