Skip to content

ci: push to main with a GitHub App token instead of a PAT - #491

Merged
Loup-Garou911XD merged 1 commit into
bombsquad-community:mainfrom
Loup-Garou911XD:ci/push-with-github-app
Sep 8, 2026
Merged

Loup-Garou911XD merged 1 commit into
bombsquad-community:mainfrom
Loup-Garou911XD:ci/push-with-github-app

Conversation

@Loup-Garou911XD

Copy link
Copy Markdown
Member

The outage

secrets.PAT was created 2022-08-31 and has expired. Every push to main now dies at actions/checkout:

fatal: could not read Username for 'https://github.com': terminal prompts disabled

That is git falling back to an interactive prompt after GitHub rejected the credential, not a permissions problem. Run 34192898501 (the #489 merge) failed there, so autopep8, the metadata pipeline and the authoritative strict test run have not executed on main since.

f4eea3d was the first commit to hand that secret to checkout, so it broke the moment it was first used.

Why an App rather than a fresh PAT

Rotating the PAT restores service until the next expiry. Fine-grained tokens cap at 366 days, so it recurs on a timer, and the failure mode is a silent red X on main that is easy to miss for a while.

An App installation token is minted per run, scoped to this repository, and revoked by the action's post step. There is no long-lived credential to rotate and nothing to silently expire. The private key does not expire.

An App can also be a ruleset bypass actor in its own right, which is exactly what this job needs and what GITHUB_TOKEN can never have.

Setup this PR depends on

Merging this alone will not make CI pass. All of the following must be in place:

  • An org-owned App with Contents: Read and write, installed on this repository
  • secrets.APP_ID and secrets.APP_PRIVATE_KEY (the whole .pem, BEGIN and END lines included)
  • The App added to the main: Require pr before merging ruleset's bypass list

The last one is the easy miss. Installing the App does not grant the bypass, it is a separate setting, and skipping it produces the same GH006: Protected branch update failed that sent this repo to a PAT in the first place. That ruleset's only bypass actor today is RepositoryRole 5 (Admin).

The header comment now carries this checklist so the next person does not have to reconstruct it.

What does not change

The self-trigger guard is untouched and still required. It keys on the committer name the three auto-commit steps set explicitly via commit_user_name, which is independent of the token, and an installation token's pushes start workflow runs exactly as a PAT's did.

The old Check PAT is configured step becomes one that names which of the two secrets is missing, so a half-finished setup identifies itself instead of surfacing as an opaque auth error five steps later. Stale PAT references elsewhere in the file are updated to match.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CSZrwNCXvibEJ9PXCW1uqi

secrets.PAT was created 2022-08-31 and has expired. Every push to main
now dies at actions/checkout with

  fatal: could not read Username for 'https://github.com': terminal
  prompts disabled

which is git falling back to an interactive prompt after GitHub rejected
the credential. autopep8, the metadata pipeline and the authoritative
strict test run have not executed on main since.

Rotating the PAT would restore it until the next expiry. An App
installation token is minted per run, scoped to this repository, and
revoked when the job ends, so there is no long-lived credential to
rotate and nothing to silently expire.

An App can also be a ruleset bypass actor in its own right, which is what
this job needs and what GITHUB_TOKEN can never have. Installing the App
does not by itself grant that bypass - it must be added to the
"main: Require pr before merging" ruleset's bypass list separately, which
the header now spells out alongside the rest of the setup.

The self-trigger guard is unaffected. It keys on the committer name the
three auto-commit steps set explicitly, not on the token, and an
installation token's pushes start workflow runs exactly as a PAT's did,
so the guard is still required.

Needs secrets.APP_ID and secrets.APP_PRIVATE_KEY; the new fail-fast step
names whichever is missing rather than letting it surface as an opaque
auth error further down.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CSZrwNCXvibEJ9PXCW1uqi
@Loup-Garou911XD
Loup-Garou911XD merged commit a4ec3c2 into bombsquad-community:main Sep 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant