From 48550885ac44cad48cb11b041c68a8e2eb93d6a3 Mon Sep 17 00:00:00 2001 From: bgoldberg122 Date: Tue, 29 Sep 2026 17:45:54 -0400 Subject: [PATCH] [IDP-1735] Add dd-octo-sts trust policy for Publishing Platform Publishing Platform authenticates to GitHub with a GitHub App private key read from Vault. This trust policy lets the pub_platform and pub_platform_internal services mint short-lived dd-octo-sts installation tokens for this repo instead, scoped to the minimum permissions their GitHub write path actually uses. Additive: it grants nothing until the services are cut over, and the identities are separately allowlisted in dd-source. Co-Authored-By: Claude Opus 5 --- .../pub-platform.publish.prod.sts.yaml | 39 +++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 .github/chainguard/pub-platform.publish.prod.sts.yaml diff --git a/.github/chainguard/pub-platform.publish.prod.sts.yaml b/.github/chainguard/pub-platform.publish.prod.sts.yaml new file mode 100644 index 000000000..e94051088 --- /dev/null +++ b/.github/chainguard/pub-platform.publish.prod.sts.yaml @@ -0,0 +1,39 @@ +# Trust policy for Datadog Publishing Platform (IDP-1735) — PRODUCTION. +# +# Lets the pub_platform and pub_platform_internal Rapid services mint +# short-lived dd-octo-sts installation tokens for this repository, replacing the +# long-lived GitHub App private key they read from Vault today +# (k8s/rapid-assets/pub-platform-internal/pub-plat-github). +# +# This repo is one of Publishing Platform's `integration_repos`: the services +# open and update integration-listing PRs against it. +# +# Permissions are the minimum the write path actually uses — blobs, trees, +# commits and refs (`contents: write`) plus opening, listing and merging pull +# requests (`pull_requests: write`). Deliberately NOT granted: `checks`, which +# is only needed for the shadow repo where APW validation runs, and any +# review / label / issue / team scope, none of which this code path touches. +# +# Services: +# https://github.com/ddoghq/dd-source/tree/main/domains/assets/apps/apis/pub_platform +# https://github.com/ddoghq/dd-source/tree/main/domains/assets/apps/apis/pub_platform_internal +# The only consumer of this token — every GitHub call is made from here: +# https://github.com/ddoghq/dd-source/blob/main/domains/integrationdevtools/shared/libs/pubplatform/services/github_pr.py +# +# Identities are allowlisted centrally in dd-source at +# domains/seceng/sit/apps/source-security/dd-octo-sts/cmd/app/static-config/auth/prod/allow.json +# +# Datacenters mirror each service's rapid.json release.placement: +# pub-platform -> us1.prod.dog, eu1.prod.dog +# pub-platform-internal -> us1.prod.dog +issuer: https://ticino.identity.local-cluster.local-dc.fabric.dog:8443/v1/issuer/sycamore + +subject_pattern: "rapid-assets\\.pub-platform@kubernetes\\.(us1|eu1)\\.prod\\.dog|rapid-assets\\.pub-platform-internal@kubernetes\\.us1\\.prod\\.dog" + +claim_pattern: + email: "rapid-assets\\.pub-platform@kubernetes\\.(us1|eu1)\\.prod\\.dog|rapid-assets\\.pub-platform-internal@kubernetes\\.us1\\.prod\\.dog" + +permissions: + contents: write + pull_requests: write + metadata: read