ci: push to main with a GitHub App token instead of a PAT - #491
Merged
Loup-Garou911XD merged 1 commit intoSep 8, 2026
Merged
Loup-Garou911XD merged 1 commit into
Loup-Garou911XD merged 1 commit into
Conversation
secrets.PAT was created 2022-08-31 and has expired. Every push to main now dies at actions/checkout with fatal: could not read Username for 'https://github.com': terminal prompts disabled which is git falling back to an interactive prompt after GitHub rejected the credential. autopep8, the metadata pipeline and the authoritative strict test run have not executed on main since. Rotating the PAT would restore it until the next expiry. An App installation token is minted per run, scoped to this repository, and revoked when the job ends, so there is no long-lived credential to rotate and nothing to silently expire. An App can also be a ruleset bypass actor in its own right, which is what this job needs and what GITHUB_TOKEN can never have. Installing the App does not by itself grant that bypass - it must be added to the "main: Require pr before merging" ruleset's bypass list separately, which the header now spells out alongside the rest of the setup. The self-trigger guard is unaffected. It keys on the committer name the three auto-commit steps set explicitly, not on the token, and an installation token's pushes start workflow runs exactly as a PAT's did, so the guard is still required. Needs secrets.APP_ID and secrets.APP_PRIVATE_KEY; the new fail-fast step names whichever is missing rather than letting it surface as an opaque auth error further down. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CSZrwNCXvibEJ9PXCW1uqi
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The outage
secrets.PATwas created 2022-08-31 and has expired. Every push to main now dies atactions/checkout:That is git falling back to an interactive prompt after GitHub rejected the credential, not a permissions problem. Run
34192898501(the #489 merge) failed there, so autopep8, the metadata pipeline and the authoritative strict test run have not executed on main since.f4eea3dwas the first commit to hand that secret to checkout, so it broke the moment it was first used.Why an App rather than a fresh PAT
Rotating the PAT restores service until the next expiry. Fine-grained tokens cap at 366 days, so it recurs on a timer, and the failure mode is a silent red X on main that is easy to miss for a while.
An App installation token is minted per run, scoped to this repository, and revoked by the action's post step. There is no long-lived credential to rotate and nothing to silently expire. The private key does not expire.
An App can also be a ruleset bypass actor in its own right, which is exactly what this job needs and what
GITHUB_TOKENcan never have.Setup this PR depends on
Merging this alone will not make CI pass. All of the following must be in place:
secrets.APP_IDandsecrets.APP_PRIVATE_KEY(the whole.pem, BEGIN and END lines included)main: Require pr before mergingruleset's bypass listThe last one is the easy miss. Installing the App does not grant the bypass, it is a separate setting, and skipping it produces the same
GH006: Protected branch update failedthat sent this repo to a PAT in the first place. That ruleset's only bypass actor today isRepositoryRole 5(Admin).The header comment now carries this checklist so the next person does not have to reconstruct it.
What does not change
The self-trigger guard is untouched and still required. It keys on the committer name the three auto-commit steps set explicitly via
commit_user_name, which is independent of the token, and an installation token's pushes start workflow runs exactly as a PAT's did.The old
Check PAT is configuredstep becomes one that names which of the two secrets is missing, so a half-finished setup identifies itself instead of surfacing as an opaque auth error five steps later. Stale PAT references elsewhere in the file are updated to match.🤖 Generated with Claude Code
https://claude.ai/code/session_01CSZrwNCXvibEJ9PXCW1uqi