Skip to content

refactor: remove ingot root creds - #60

Merged
alanshaw merged 2 commits into
mainfrom
ash/refactor/remove-ingot-root-creds
Sep 15, 2026
Merged

alanshaw merged 2 commits into
mainfrom
ash/refactor/remove-ingot-root-creds

Conversation

@alanshaw

Copy link
Copy Markdown
Member

Ingot root access is now disabled.

refs fil-forge/ingot#142 fil-forge/smelt#42

Copilot AI lite review requested due to automatic review settings September 15, 2026 10:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Existing root credentials are not purged from previously provisioned nodes; add and document a privileged cleanup migration.

Pull request overview

Removes deprecated Ingot root credentials now that root access is disabled.

Changes:

  • Stops generating, loading, and exporting root credentials.
  • Removes root credential fields from development and staging configurations.
  • Updates related secret documentation.
File summaries
File Summary
scripts/host/keygen.sh Removes root credential generation; existing credentials still require privileged cleanup.
scripts/host/deploy-apps.sh Stops loading and exporting root credentials.
nodes/staging/apps/config/ingot/config.yaml.tpl Removes root credential settings.
nodes/dev/apps/config/ingot/config.yaml.tpl Removes root credential settings and documentation.
nodes/dev/apps/compose.yml Updates the secret configuration comment.
Review details

Suppressed comments (1)

scripts/host/keygen.sh:168

  • This keeps the old credentials in place on every node that was provisioned before this change: generate_password only creates missing fields, and removing the two calls does not delete the existing ingot#root_access_key/ingot#root_secret_key values from OpenBao. Because the deploy policy only grants create/read/update/patch (scripts/host/provision-platform.sh:180-187), normal re-provisioning cannot scrub them, so add a privileged migration/cleanup step and document how existing nodes are purged.
  if bao_has "$path" "$field"; then
    echo "  $path#$field already set"
    return 0
  fi
  bao_put_if_absent "$path" "$field" "$(openssl rand -hex 32)"
  • Files reviewed: 5/5 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@alanshaw
alanshaw requested a review from bajtos September 15, 2026 10:44

@bajtos bajtos left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

Existing root credentials are not purged from previously provisioned nodes; add and document a privileged cleanup migration.

I think that's fine, no need to purge them.

@alanshaw
alanshaw merged commit 93fe809 into main Sep 15, 2026
4 checks passed
@alanshaw
alanshaw deleted the ash/refactor/remove-ingot-root-creds branch September 15, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants