feat(identity): bind personas to workload authority #7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/persona-workload-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
First-class persona workload identity: deterministic Kubernetes/SPIFFE identity, dedicated Keycloak service accounts, explicit OPA roles, immutable PostgreSQL bindings, Forgejo receipts, rotating SPIRE TLS trust, and production Argo wiring. Validation: 171 focused tests, Ruff, Helm lint, Kubernetes server-side dry run, live TLS verification, and PostgreSQL 16 integration. Depends on forgejo-codetether-agent PR #2 for receipt projection.
⚠️ CodeTether Fix
Task ended with status
failed.Error: OpenAI Codex ChatGPT backend is disabled. Configure OPENAI_API_KEY for the official OpenAI API, or set CODETETHER_OPENAI_CODEX_ALLOW_CHATGPT_BACKEND=1 to opt in.
Task:
d518b65e-ae70-477a-839c-884cb1dcce6f⚠️ CodeTether Fix
Task ended with status
failed.Error: OpenAI Codex ChatGPT backend is disabled. Configure OPENAI_API_KEY for the official OpenAI API, or set CODETETHER_OPENAI_CODEX_ALLOW_CHATGPT_BACKEND=1 to opt in.
Task:
9c8fc60b-0e80-4c28-8bc2-e54df60bf6f1