[IDP-1735] Add dd-octo-sts trust policy for Publishing Platform - #3190
Closed
bgoldberg122 wants to merge 1 commit into
Closed
bgoldberg122 wants to merge 1 commit into
bgoldberg122 wants to merge 1 commit into
Conversation
Publishing Platform authenticates to GitHub with a GitHub App private key read from Vault. This trust policy lets the pub_platform and pub_platform_internal services mint short-lived dd-octo-sts installation tokens for this repo instead, scoped to the minimum permissions their GitHub write path actually uses. Additive: it grants nothing until the services are cut over, and the identities are separately allowlisted in dd-source. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Validation ReportAll 11 validations passed. Show details
|
Collaborator
Author
|
Closing unmerged — IDP-1735 has been deprioritized. All findings from this work (the sycamore-vs-Vault issuer correction, the Python support verdict, the egress gap, and the full Phase B plan) are recorded on the Jira card: https://datadoghq.atlassian.net/browse/IDP-1735 The branch is left in place, so this PR can be reopened as-is when the card is picked back up. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds
.github/chainguard/pub-platform.publish.prod.sts.yaml, a dd-octo-sts trust policy letting the Datadog Publishing Platform services mint short-lived, repo-scoped GitHub installation tokens for this repository.One new file. No existing file is modified. Jira: IDP-1735.
Why
Publishing Platform authenticates to GitHub today with a long-lived GitHub App private key read from Vault (
k8s/rapid-assets/pub-platform-internal/pub-plat-github) — seeconfig.pyand theAuth.AppAuth(...)call sites inservices/github_pr.py. dd-octo-sts replaces that with 1-hour tokens minted per exchange against an OIDC identity, so there is no durable credential to leak or rotate.This repo's role: one of Publishing Platform's
integration_repos— the services open and update integration-listing PRs against it.The calling services:
pub_platform(us1.prod.dog,eu1.prod.dog)pub_platform_internal(us1.prod.dog)Safe to merge now — and merging is a prerequisite
This is additive and inert. A trust policy grants nothing by itself: a token is only ever issued if (a) this policy is present on the default branch, and (b) the calling identity is in the central dd-octo-sts allowlist. Nothing calls the exchange for this repo until the application cutover ships, so merging this changes no behaviour today.
It does need to merge, though: this policy being on the default branch is a hard prerequisite for the cutover. dd-octo-sts reads trust policies from the default branch only, so a policy sitting in an unmerged PR is invisible. It is opened as a draft because the reviewable question is the permission set, not the timing — please convert and merge whenever the scope below looks right to you.
Permissions, and why each one
contents: writecreate_git_blob,create_git_tree,create_git_ref,get_git_tree,get_branch,branch.edit,ref.delete,merge.pull_requests: writecreate_pull,get_pulls,get_pull, and the squash merge.metadata: readDeliberately not requested:
checks— APW check polling (_get_branch_and_apw_check_status) is only ever called withpub_platform_repo, the shadow repo. This repo never has its checks read, so it gets nochecksgrant. Only one of the six target repos does.team_utils.py), not GitHub.I derived this from a full inventory of every GitHub call in
github_pr.pyrather than copying a template. Thesubject_patternis an anchored alternation over exactly the identity/datacenter pairs each service is actually placed in per itsrapid.jsonrelease.placement— it does not glob the datacenter.Why the sycamore issuer
The supported Python route to an ID token is
dd_internal_authentication'sJWTInternalServiceAuthClientTokenManagerwithissuer="sycamore", which mints a Ticino token whose identifying claim is the email-shaped<namespace>.<service>@kubernetes.<datacenter>. The legacy per-datacenter Vault issuers (and their opaque UUID subjects, as inopenvex-worker-ghsa-prod.sts.yaml) would never match a token minted this way. This matches every existing Python dd-octo-sts consumer, e.g.pipeline_ai, and the shape ofairflow-ai-guard.false-positive.create-pr.prod.sts.yaml.Dependencies
config.py,GITHUB_AUTH_CONFIG.md). This PR touches neither, so it is independent of their ordering.Test plan
dd-octo-sts checkagainst this repo once both this PR and the allowlist PR have merged, confirming the policy and allowlist agree before any code changepub-platform-staging(its own policy PR) ahead of any prod cutover🤖 Generated with Claude Code