Skip to content

Rotate credentials for ci-builder env#2135

Draft
Alex-Welsh wants to merge 1 commit intostackhpc/2025.1from
ci-builder-cred-rotation
Draft

Rotate credentials for ci-builder env#2135
Alex-Welsh wants to merge 1 commit intostackhpc/2025.1from
ci-builder-cred-rotation

Conversation

@Alex-Welsh
Copy link
Member

Created a new user (read only) for pulling package repos from Ark, instead of using the AIO user again
Also changed the vault PW be unique (added to password manager)
Same rules apply as normal, will need to update the secret in GitHub and backport once merged

@Alex-Welsh Alex-Welsh requested a review from a team as a code owner February 6, 2026 15:59
Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request successfully rotates credentials for the ci-builder environment. It introduces a new dedicated read-only user, skc-ci-builder-reader, for pulling package repositories from Ark, replacing the previous skc-ci-aio user. Additionally, the associated vault passwords for both stackhpc_repo_mirror_password and stackhpc_docker_registry_password have been updated. These changes align with the stated objective of enhancing security by using unique and appropriately scoped credentials.

@Alex-Welsh Alex-Welsh marked this pull request as draft February 6, 2026 16:01
@Alex-Welsh
Copy link
Member Author

Converting to draft so no one merges this until next week. I don't want to deal with any fallout over the weekend and I'll be off on Monday

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant