Skip to content

feat(octo-sts): grant guarded-package-repos read access to stereo#240

Open
astrojerms wants to merge 1 commit into
chainguard-dev:mainfrom
astrojerms:add-stereo-to-guarded-package-repos
Open

feat(octo-sts): grant guarded-package-repos read access to stereo#240
astrojerms wants to merge 1 commit into
chainguard-dev:mainfrom
astrojerms:add-stereo-to-guarded-package-repos

Conversation

@astrojerms

@astrojerms astrojerms commented Jun 5, 2026

Copy link
Copy Markdown
Member

What

Add stereo to the repositories list for the guarded-package-repos octo-sts identity.

Why

chart-iamguarded-*'s chart source are being moved into chainguard-dev/stereo. Local builds in stereo auto-mint a guarded-package-repos octo-sts token (chainctl auth octo-sts --identity=guarded-package-repos --scope=chainguard-dev) to clone chart sources via the auth/github melange pipeline. That identity could read the iamguarded repos but not stereo, so make package/chart-iamguarded-common failed to clone its source. This grants the missing read access.

chart-iamguarded-common's chart source moved into chainguard-dev/stereo.
stereo's local builds auto-mint a guarded-package-repos octo-sts token to
clone chart sources, but that identity lacked read access to stereo, so
`make package/chart-iamguarded-common` failed to clone. Add stereo to the
allowed repositories.
@astrojerms astrojerms marked this pull request as ready for review June 5, 2026 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants