ci(site): preview unfoldhq.dev DNS with a read-only token from OpenBao #222

Merged
ryangr0 merged 1 commit from ryangr0/dns-preview-over-openbao into development 2026-10-04 16:01:03 +00:00 AGit
Owner

CI previews unfoldhq.dev DNS with a read-only token it fetches from OpenBao per run, and never holds a token that can change DNS (homelab-cluster ADR-0061).

  • on_dns_change.yml calls webgrip/workflows dnscontrol.yml v2.8.0 with openbao-role: ci-unfold. Each job exchanges its Forgejo OIDC token for a ten-minute OpenBao token that reads only secret/cloudflare/dns/unfoldhq-dev-ro.
  • Preview runs on a push to development that changes the zone, or by hand; drift runs daily. The push job and the CLOUDFLARE_DNS_TOKEN gate are removed.
  • The deploy guide, the CI table and the site's AGENTS.md describe the new lane. They say plainly that the in-cluster reconciler that applies changes is not running yet.

Already live in the homelab: the cloudflare-dns-token-minter CronJob minted per-zone dns-ro-* and dns-rw-* tokens for unfoldhq.dev and twente.dev, and they are in OpenBao. The ci-unfold role and policy are configured.

Tested: scripts/workflow-policy.test.cjs (22/22) and mise run docs-check pass locally. The real OIDC exchange runs for the first time after merge, when the next push to development touches the zone, or on a manual run.

🤖 Generated with Claude Code

CI previews `unfoldhq.dev` DNS with a read-only token it fetches from OpenBao per run, and never holds a token that can change DNS ([homelab-cluster ADR-0061](https://forgejo.webgrip.dev/webgrip/homelab-cluster/src/branch/main/docs/techdocs/docs/adr/adr-0061-ci-reads-over-oidc-writes-from-the-cluster.md)). - `on_dns_change.yml` calls `webgrip/workflows` `dnscontrol.yml` v2.8.0 with `openbao-role: ci-unfold`. Each job exchanges its Forgejo OIDC token for a ten-minute OpenBao token that reads only `secret/cloudflare/dns/unfoldhq-dev-ro`. - Preview runs on a push to `development` that changes the zone, or by hand; drift runs daily. The push job and the `CLOUDFLARE_DNS_TOKEN` gate are removed. - The deploy guide, the CI table and the site's AGENTS.md describe the new lane. They say plainly that the in-cluster reconciler that applies changes is not running yet. **Already live in the homelab:** the `cloudflare-dns-token-minter` CronJob minted per-zone `dns-ro-*` and `dns-rw-*` tokens for `unfoldhq.dev` and `twente.dev`, and they are in OpenBao. The `ci-unfold` role and policy are configured. **Tested:** `scripts/workflow-policy.test.cjs` (22/22) and `mise run docs-check` pass locally. The real OIDC exchange runs for the first time after merge, when the next push to `development` touches the zone, or on a manual run. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ci(site): preview unfoldhq.dev DNS with a read-only token from OpenBao
All checks were successful
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 37s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 41s
[Workflow] On Pull Request / checks (pull_request) Successful in 6m27s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
1b8453deda
on_dns_change.yml now calls webgrip/workflows dnscontrol.yml v2.8.0 on
the OpenBao role ci-unfold: each run exchanges its Forgejo OIDC token
for a ten-minute read of secret/cloudflare/dns/unfoldhq-dev-ro, a
token scoped to this one zone. The workflow previews on development
and checks drift daily; the push job and the CLOUDFLARE_DNS_TOKEN gate
are gone, because CI no longer holds a DNS write token
(homelab-cluster ADR-0061). Applying moves to an in-cluster
reconciler that is not running yet; the site deploy guide says so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 merged commit cb65305275 into development 2026-10-04 16:01:03 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!222
No description provided.