Repository navigation
feat(worker): hosted identity service — zero-config agentdiff[bot] tokens - #38
Merged
Merged
Conversation
…kens Stateless Cloudflare Worker (free tier) that mints 1h installation tokens for the project's AgentDiff App: verifies the caller's Actions token against the claimed repo, confirms the App is installed, mints, returns. No storage, no logs. Generated workflows now pick identity from three tiers — self-managed App secrets, hosted service, or github-actions[bot] — degrading gracefully. Deployment checklist in worker/README.md.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A stateless Cloudflare Worker (free tier) that mints 1-hour GitHub App installation tokens, plus a three-tier identity ladder in the generated approve workflow: self-managed App secrets → hosted token service →
github-actions[bot]. Each tier is automatic and degrades gracefully — a repo with no App configured still gets the full zero-setup bot (PR #37).Why
Completes the CodeRabbit-tier UX at $0: install the App once → the bot is branded
agentdiff[bot]everywhere, no secrets or variables per repo. The Worker holds the App key; it stores nothing (no KV/DB/logs) and the security contract is enforced in code: caller's Actions token must already have access to the claimed repo, the App must be installed there, tokens expire in ≤1h.How
worker/src/worker.js:POST /token(verify caller → app JWT via WebCrypto RS256 with PKCS#1→PKCS#8 DER normalization — GitHub issues PKCS#1 PEMs — → installation check → mint),GET /app(install redirect),GET /(health)init_wizard.py:TOKEN_SERVICE_URLconstant baked into templates; token-selection step chainworker/README.md: deploy + GitHub App permission checklist (user-run, browser steps)test_token_service.py): routes, security invariants, stateless config, template ladder — plus full YAML validationTesting
worker/README.md) — Worker deploy + App creation are user-run browser/console steps by designChecklist
make lint+ full suite green[Unreleased]entryLinks to
context/ROADMAP.mdPhase M / 0.5.0 (user decision: pull K3-lite forward — identity service only, not a hosted eval backend).