Skip to content

ci: weekly production smoke for workspace service tokens - #1040

Merged
Zach Dunn (zachdunn) merged 6 commits into
mainfrom
claude/service-token-smoke
Sep 25, 2026
Merged

Zach Dunn (zachdunn) merged 6 commits into
mainfrom
claude/service-token-smoke

Conversation

@zachdunn

@zachdunn Zach Dunn (zachdunn) commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

In plain terms

Adds a small production check for workspace service tokens. It uses the UPLOADS_SERVICE_TOKEN repo secret the way a CI job would: the CLI built from this checkout, with only the token set. It uploads a tiny image and checks the upload is attributed to the service token.

What it does / what it is not

  • Checks two things. The CLI reads the workspace from the token, with no UPLOADS_WORKSPACE set. A gh.*-tagged upload gets gh.uploader-kind: service and a label in gh.uploader, with no gh.uploader-id.
  • Service tokens minted from the UI have no delete scope, so the smoke overwrites one fixed key (screenshots/smoke/service-token.webp, --replace). Only one smoke file ever exists.
  • Runs weekly (Mondays), on demand, and on PRs that change the workflow or its script. Fork PRs are skipped because they get no secrets.
  • Warns, without failing, if the secret starts with up_ (a token minted before feat: give workspace service tokens a ups_ prefix #1039). Never prints the token.
  • Does not post a PR comment. The comment path depends on which repos the token's workspace has linked.

Test plan

  • The smoke passes on this PR against production. It uploaded to default and attributed the upload to the token's label as a service.
  • Removed the two stray files that earlier failed iterations uploaded.

@changeset-bot

changeset-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 31a5ddf

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (2)
  • coderabbit:review
  • review
🚫 Excluded labels (none allowed) (1)
  • wip

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: add5c2b4-a08e-4ea0-930a-63f2b81eb93d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zachdunn
Zach Dunn (zachdunn) merged commit a60fe13 into main Sep 25, 2026
4 checks passed
@zachdunn
Zach Dunn (zachdunn) deleted the claude/service-token-smoke branch September 25, 2026 23:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant