Skip to content

Authorize SEP generated reference publication - #1215

Merged
danbarr merged 2 commits into
mainfrom
authorize-sep-reference-publisher
Oct 6, 2026
Merged

danbarr merged 2 commits into
mainfrom
authorize-sep-reference-publisher

Conversation

@danbarr

@danbarr danbarr commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Authorize SEP's generated-reference publisher to open public documentation PRs through OctoSTS. The policy grants only contents: write and pull_requests: write, restricted to SEP's standard OIDC subject on main, its immutable repository and owner IDs, and the exact standalone publish-docs-references.yml workflow on main.

Complete the SEP reference source mappings for Enterprise Manager, Connector Gateway, and AI Gateway management. Generation and private-source reads happen in SEP; this public repository receives a generated-reference PR and needs no private-repo credentials.

Pin token exchanges to the stacklok-octosts App with app: "4886385". The quoted ID is a string, and the upgraded OctoSTS deployment supports this field. This prevents exchanges from routing through another configured App.

Type of change

  • Documentation update

Related issues/PRs

Validation

  • Policy schema validation and positive/negative identity checks passed, including rejection of missing or incorrect repository IDs, another workflow, tag/feature refs, and PR subjects.
  • Confirmed SEP's repository OIDC settings report the standard subject and immutable subjects disabled; repository and owner IDs match GitHub's live API.
  • Confirmed the public main ruleset requires PR review and App 4886385 is not a bypass actor.
  • Policy schema validation confirms the App pin is a string; Prettier and git diff --check passed.
  • Production docs build passed. The existing API-reference HTML-minifier warning remains until the generated-reference backfill lands; policy and metadata changes do not refresh the specs themselves.
  • Live token exchange remains untested until this policy and the SEP workflow land on their default branches. The OctoSTS App must be installed on docs-website.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:11
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs-website Ready Ready Preview Oct 6, 2026 8:46pm UTC

Request Review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive token exchange and private SEP source paths cannot be verified end to end before both workflows land.

Review effort: Balanced
Findings: None

What changed in this PR

Authorizes SEP to publish generated references securely and records their source mappings.

Changes:

  • Adds a narrowly scoped OctoSTS policy.
  • Maps three SEP API specifications to public destinations.
File Description
.github/​chainguard/​sep-docs-pr.sts.yaml Defines publisher identity constraints and permissions.
.github/​upstream-projects.yaml Adds SEP reference source mappings.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@danbarr
danbarr requested a review from Nashon-Steffen October 6, 2026 20:17
@danbarr
danbarr merged commit ddb7568 into main Oct 6, 2026
6 checks passed
@danbarr
danbarr deleted the authorize-sep-reference-publisher branch October 6, 2026 20:47

This branch was successfully deployed

1 active deployment
Preview — 8ad6e44d Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants