feat(orb): self-host broker client — brokered installation tokens - #1341
Merged
Conversation
Completes the Orb token broker end-to-end (server: #1330/#1332). A brokered self-host holds no GitHub App private key — it installs the central Orb App and sets the operator-issued ORB_ENROLLMENT_SECRET. createInstallationToken now sources tokens from the central Orb (POST /v1/orb/token) when that secret is present, caching them in the same in-isolate token cache as the App-key path (~1 mint/hour/install). Cloud never sets the secret, so the branch is inert there → byte-identical. - src/orb/broker-client.ts: isOrbBrokerMode (secret-presence gate) + fetchBrokeredInstallationToken (exchange secret → {token, installationId, expiresAt}; injectable fetch + 10s timeout; throws on non-OK / tokenless body). - src/github/app.ts: the broker branch slots in at the single token chokepoint, right after the cache check. - No App-key fallback by design (a brokered self-host has none) — a broker outage fails the request exactly like an App-key mint failure, and the queue's retry/dead-letter handling covers a transient blip. The secret is sent as a Bearer over the https default and never logged (errors carry only the status). Advances #1255. (Maintainer-OAuth self-enrollment remains a follow-up; today enrollments are operator-issued.)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1341 +/- ##
=======================================
Coverage 95.26% 95.26%
=======================================
Files 187 188 +1
Lines 20359 20377 +18
Branches 7339 7347 +8
=======================================
+ Hits 19395 19413 +18
Misses 378 378
Partials 586 586
🚀 New features to boost your workflow:
|
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
This was referenced Jun 25, 2026
JSONbored
added a commit
that referenced
this pull request
Jun 25, 2026
…1355) Closes the brokered self-host loop (#1255): the container now self-registers its public relay URL with the central Orb on startup, so the Orb forwards this install's events to it — no manual curl. The container computes its relay URL from PUBLIC_API_ORIGIN + /v1/orb/relay and POSTs it to the broker with its enrollment secret. registerOrbRelayTarget (src/orb/broker-client.ts) is BEST-EFFORT + fire-and-forget: skipped unless broker mode + PUBLIC_API_ORIGIN are set, and any failure (Orb down, install not registered yet, non-public origin rejected by the Orb's SSRF check) just means no relay until the next boot — it never throws or blocks startup. Wired into the selfhost boot alongside the orb-export hook (server.ts, the codecov-ignored process entry). End-to-end now: install Orb App → self-enroll (admin-verified, #1348) → broker tokens (#1341) → boot auto-registers relay (this) → Orb forwards events (#1352) → relay receiver verifies + enqueues (#1354) → review + act. Advances #1255.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Completes the Orb token broker end-to-end (the server side shipped in #1330/#1332). A brokered self-host holds no GitHub App private key — it installs the central Orb App and sets the operator-issued
ORB_ENROLLMENT_SECRET.createInstallationTokennow sources tokens from the central Orb (POST /v1/orb/token) when that secret is present, caching them in the same in-isolate token cache as the App-key path (~1 mint/hour/install). Cloud never sets the secret, so the branch is inert there → byte-identical.src/orb/broker-client.ts—isOrbBrokerMode(the secret-presence gate) +fetchBrokeredInstallationToken(exchange secret →{token, installationId, expiresAt}; injectable fetch + 10s timeout; throws on non-OK / tokenless body).src/github/app.ts— the broker branch slots in at the single token chokepoint, right after the cache check.Validation
npm run test:cigreen./v1/orb/tokenand is cached); 100% branch coverage on the diff (default/custom broker URL, trailing-slash strip, present/absent expiry + installationId, empty-secret defensive branch, non-OK + tokenless throws, and the cloud byte-identical path).Safety
ORB_ENROLLMENT_SECRETpresence; cloud sets none → byte-identical. No secret in logs/code. No new wrangler var (self-host secret).Advances #1255. (Maintainer-OAuth self-enrollment remains a clean follow-up — today enrollments are operator-issued.)