Skip to content

Retire completed auth and broker compatibility aliases - #80

Merged
GoonMachine merged 2 commits into
mainfrom
codex/upstream-legacy-cleanup-20260715
Jul 15, 2026
Merged

Retire completed auth and broker compatibility aliases#80
GoonMachine merged 2 commits into
mainfrom
codex/upstream-legacy-cleanup-20260715

Conversation

@fineas-bot

@fineas-bot fineas-bot Bot commented Jul 15, 2026

Copy link
Copy Markdown

Summary

  • require Slackbot session service authentication through the canonical Authorization: Bearer path and reject the retired X-Api-Key lane
  • bootstrap only the canonical github-app broker credential; remove the unused umbrella enable flag and compatibility alias settings
  • remove documentation for the retired standalone token-broker chart settings

Deliberately retained

  • the unlabeled-sandbox NetworkPolicy bridge remains until the schema-forward rollback/reforward window is retired
  • the overlay-image fallback remains until the merged repo-backed runtime is pinned and fresh-sandbox canaries pass
  • TipLink authorization, Slack channel/RLS boundaries, workflow credential scrubbing, and migration history remain unchanged

Validation

  • bash contrib/chart/tests/test_overlay_image_compat.sh
  • helm lint contrib/chart
  • exact Fineas infra values render against this chart
  • JSON and shell syntax checks
  • three independent compatibility reviews; no blockers

Rust is not installed on the host, so the new deterministic auth unit test relies on PR CI for execution. CodeQL is inherited and intentionally out of scope.

Paired active-config cleanup: https://github.com/TipLink/fineas-centaur-infra/pull/156

fineas-bot Bot added 2 commits July 15, 2026 14:58
Use the canonical Bearer and GitHub broker paths now that all active callers and credentials have migrated.
@GoonMachine
GoonMachine merged commit 991cba5 into main Jul 15, 2026
36 of 37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant