Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/chainguard/pub-platform.publish.prod.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# Trust policy for Datadog Publishing Platform (IDP-1735) — PRODUCTION.
#
# Lets the pub_platform and pub_platform_internal Rapid services mint
# short-lived dd-octo-sts installation tokens for this repository, replacing the
# long-lived GitHub App private key they read from Vault today
# (k8s/rapid-assets/pub-platform-internal/pub-plat-github).
#
# This repo is one of Publishing Platform's `integration_repos`: the services
# open and update integration-listing PRs against it.
#
# Permissions are the minimum the write path actually uses — blobs, trees,
# commits and refs (`contents: write`) plus opening, listing and merging pull
# requests (`pull_requests: write`). Deliberately NOT granted: `checks`, which
# is only needed for the shadow repo where APW validation runs, and any
# review / label / issue / team scope, none of which this code path touches.
#
# Services:
# https://github.com/ddoghq/dd-source/tree/main/domains/assets/apps/apis/pub_platform
# https://github.com/ddoghq/dd-source/tree/main/domains/assets/apps/apis/pub_platform_internal
# The only consumer of this token — every GitHub call is made from here:
# https://github.com/ddoghq/dd-source/blob/main/domains/integrationdevtools/shared/libs/pubplatform/services/github_pr.py
#
# Identities are allowlisted centrally in dd-source at
# domains/seceng/sit/apps/source-security/dd-octo-sts/cmd/app/static-config/auth/prod/allow.json
#
# Datacenters mirror each service's rapid.json release.placement:
# pub-platform -> us1.prod.dog, eu1.prod.dog
# pub-platform-internal -> us1.prod.dog
issuer: https://ticino.identity.local-cluster.local-dc.fabric.dog:8443/v1/issuer/sycamore

subject_pattern: "rapid-assets\\.pub-platform@kubernetes\\.(us1|eu1)\\.prod\\.dog|rapid-assets\\.pub-platform-internal@kubernetes\\.us1\\.prod\\.dog"

claim_pattern:
email: "rapid-assets\\.pub-platform@kubernetes\\.(us1|eu1)\\.prod\\.dog|rapid-assets\\.pub-platform-internal@kubernetes\\.us1\\.prod\\.dog"

permissions:
contents: write
pull_requests: write
metadata: read
Loading