Seen from ace on 2026-09-30 (W15 snake, W3 car-hunter).
The builder clones the forge as gitea user mesh_novox_builder (/var/lib/builder/workspace/git-credentials). A private repo fails: remote: Repository not found — it is neither a site admin nor a collaborator.
The operator's intent: the builder has full access to gitea ("make sure our builder has full access to gitea").
The mesh's own gitea tool (ask gitea gitea_api, as mesh-admin) cannot do it: PATCH /admin/users/mesh_novox_builder {admin:true} → 403 token does not have at least one of required scope(s), required=[write:admin], token scope=write:issue,write:repository,read:user.
Workaround in use: a read collaboration per private repo through PUT /repos/<owner>/<repo>/collaborators/mesh_novox_builder (fits write:repository), i.e. every new private repo needs a manual step — the very thing the mesh should settle.
Asks for novox / the gitea module:
The builder's forge identity gets access to every repo the mesh may build (site admin, or the seat grants it at registration).
The token the gitea seat mints for the mesh carries write:admin (or whatever scope the seat needs to manage its own users), so the mesh can settle this itself.
Seen from ace on 2026-09-30 (W15 snake, W3 car-hunter).
- The builder clones the forge as gitea user `mesh_novox_builder` (`/var/lib/builder/workspace/git-credentials`). A private repo fails: `remote: Repository not found` — it is neither a site admin nor a collaborator.
- The operator's intent: **the builder has full access to gitea** ("make sure our builder has full access to gitea").
- The mesh's own gitea tool (`ask gitea gitea_api`, as `mesh-admin`) cannot do it: `PATCH /admin/users/mesh_novox_builder {admin:true}` → `403 token does not have at least one of required scope(s), required=[write:admin], token scope=write:issue,write:repository,read:user`.
- Workaround in use: a read collaboration per private repo through `PUT /repos/<owner>/<repo>/collaborators/mesh_novox_builder` (fits `write:repository`), i.e. every new private repo needs a manual step — the very thing the mesh should settle.
Asks for novox / the gitea module:
1. The builder's forge identity gets access to every repo the mesh may build (site admin, or the seat grants it at registration).
2. The token the gitea seat mints for the mesh carries `write:admin` (or whatever scope the seat needs to manage its own users), so the mesh can settle this itself.
Related: #228 (keycloak admin credential), #227 (resolver).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Seen from ace on 2026-09-30 (W15 snake, W3 car-hunter).
mesh_novox_builder(/var/lib/builder/workspace/git-credentials). A private repo fails:remote: Repository not found— it is neither a site admin nor a collaborator.ask gitea gitea_api, asmesh-admin) cannot do it:PATCH /admin/users/mesh_novox_builder {admin:true}→403 token does not have at least one of required scope(s), required=[write:admin], token scope=write:issue,write:repository,read:user.PUT /repos/<owner>/<repo>/collaborators/mesh_novox_builder(fitswrite:repository), i.e. every new private repo needs a manual step — the very thing the mesh should settle.Asks for novox / the gitea module:
write:admin(or whatever scope the seat needs to manage its own users), so the mesh can settle this itself.Related: #228 (keycloak admin credential), #227 (resolver).