The builder cannot clone private repos, and the mesh's gitea token cannot grant it access (no write:admin) #229

Open
opened 2026-09-30 18:59:45 +00:00 by mesh-admin · 0 comments
Contributor

Seen from ace on 2026-09-30 (W15 snake, W3 car-hunter).

  • The builder clones the forge as gitea user mesh_novox_builder (/var/lib/builder/workspace/git-credentials). A private repo fails: remote: Repository not found — it is neither a site admin nor a collaborator.
  • The operator's intent: the builder has full access to gitea ("make sure our builder has full access to gitea").
  • The mesh's own gitea tool (ask gitea gitea_api, as mesh-admin) cannot do it: PATCH /admin/users/mesh_novox_builder {admin:true} → 403 token does not have at least one of required scope(s), required=[write:admin], token scope=write:issue,write:repository,read:user.
  • Workaround in use: a read collaboration per private repo through PUT /repos/<owner>/<repo>/collaborators/mesh_novox_builder (fits write:repository), i.e. every new private repo needs a manual step — the very thing the mesh should settle.

Asks for novox / the gitea module:

  1. The builder's forge identity gets access to every repo the mesh may build (site admin, or the seat grants it at registration).
  2. The token the gitea seat mints for the mesh carries write:admin (or whatever scope the seat needs to manage its own users), so the mesh can settle this itself.

Related: #228 (keycloak admin credential), #227 (resolver).

Seen from ace on 2026-09-30 (W15 snake, W3 car-hunter). - The builder clones the forge as gitea user `mesh_novox_builder` (`/var/lib/builder/workspace/git-credentials`). A private repo fails: `remote: Repository not found` — it is neither a site admin nor a collaborator. - The operator's intent: **the builder has full access to gitea** ("make sure our builder has full access to gitea"). - The mesh's own gitea tool (`ask gitea gitea_api`, as `mesh-admin`) cannot do it: `PATCH /admin/users/mesh_novox_builder {admin:true}` → `403 token does not have at least one of required scope(s), required=[write:admin], token scope=write:issue,write:repository,read:user`. - Workaround in use: a read collaboration per private repo through `PUT /repos/<owner>/<repo>/collaborators/mesh_novox_builder` (fits `write:repository`), i.e. every new private repo needs a manual step — the very thing the mesh should settle. Asks for novox / the gitea module: 1. The builder's forge identity gets access to every repo the mesh may build (site admin, or the seat grants it at registration). 2. The token the gitea seat mints for the mesh carries `write:admin` (or whatever scope the seat needs to manage its own users), so the mesh can settle this itself. Related: #228 (keycloak admin credential), #227 (resolver).
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#229