builder: a clone may offer the forge's credential, through git's own store #65

Merged
jschoubben merged 1 commits from feat/builder-clones-with-the-forges-credential into main 2026-09-25 19:54:40 +00:00
Owner

A private repository could not be built: the builder clones anonymously and had no way to say who it is (novox.be and de-spiegel, both private, are the first modules to hit this — their nox-mesh conversion branches are pushed and locally proven, waiting on this).

The builder already holds exactly one credential to exactly the right place — the package-registry binding and its sealed secret: one gitea user whose password answers npm and git alike. A clone now offers that, and nothing new is minted or carried.

Offered, never pushed. The credential is written as a git credential-store file (0600, in the workspace, never argv) and named with -c credential.helper, so git itself decides when it applies — only on an authentication challenge, and only for the URL it was written for, scheme, host and port included. A public repository clones exactly as before; a repository on any other host is never shown it. The same store rides along on an artifact's own cross-repo context clone.

Private repos are registered by the forge's binding address (http://novox.internal:20000/...) so the credential's URL matches the clone's — which is also the address that works with no public round trip.

Tested: the store is named and holds the URL at 0600, the secret never reaches a command line, a credential-less build is byte-identical to before, and the context clone carries the same offer. Depends operationally (not code-wise) on mesh-catalog#71 — the gitea provisioner fix that makes mesh_novox_builder actually exist.

A private repository could not be built: the builder clones anonymously and had no way to say who it is (`novox.be` and `de-spiegel`, both private, are the first modules to hit this — their nox-mesh conversion branches are pushed and locally proven, waiting on this). The builder already holds exactly one credential to exactly the right place — the package-registry binding and its sealed secret: one gitea user whose password answers npm and git alike. A clone now offers that, and nothing new is minted or carried. **Offered, never pushed.** The credential is written as a git credential-store file (0600, in the workspace, never argv) and named with `-c credential.helper`, so git itself decides when it applies — only on an authentication challenge, and only for the URL it was written for, scheme, host and port included. A public repository clones exactly as before; a repository on any other host is never shown it. The same store rides along on an artifact's own cross-repo context clone. Private repos are registered by the forge's binding address (`http://novox.internal:20000/...`) so the credential's URL matches the clone's — which is also the address that works with no public round trip. Tested: the store is named and holds the URL at 0600, the secret never reaches a command line, a credential-less build is byte-identical to before, and the context clone carries the same offer. Depends operationally (not code-wise) on mesh-catalog#71 — the gitea provisioner fix that makes `mesh_novox_builder` actually exist.
jschoubben added 1 commit 2026-09-25 19:47:46 +00:00
A private repository could not be built: the builder clones anonymously,
and had no way to say who it is. It already holds exactly one credential
to exactly the right place — the package-registry binding and its sealed
secret, one gitea user whose password answers npm and git alike — so a
clone now offers that, and nothing new is minted or carried.

Offered, never pushed: the credential is written as a git
credential-store file (0600, in the workspace, never argv) and named
with -c credential.helper, so git itself decides when it applies — only
on an authentication challenge, and only for the URL it was written
for, scheme, host and port included. A public repository clones exactly
as before; a repository on any other host is never shown it. The same
store rides along on an artifact's own context clone, so a private
module with a private context builds too.
jschoubben merged commit f8919e2079 into main 2026-09-25 19:54:40 +00:00
jschoubben deleted branch feat/builder-clones-with-the-forges-credential 2026-09-25 19:54:40 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#65