7e0ff9ab06
The repo carried a gitignored .secrets/ directory with four files. Two of them
(context7-token, gitea-token) were byte-identical copies of variables the login
shell already exported. One (gitea-host) is not a secret. The fourth
(worker-gitea-token) was the only copy anywhere, and nothing exported it, so
bridged read gitTokenEnv from an environment that never had it and every worker
push got an empty token.
All four values now live in the operator's single sourced secrets file, verified by
sha256 before the copies were removed. opencode.json reads them as {env:...}, which
.mcp.json already did. A second copy of a secret is the problem: the copy you forget
is the one that leaks or goes stale.
This makes worktree isolation load-bearing rather than a workaround. opencode.json is
tracked, so it lands in every worktree. It used to fail there, because {file:.secrets/}
pointed at files a worktree never receives and OpenCode refuses to start on a dangling
reference. With {env:...} the reference resolves, and a member would silently inherit
the primary's admin-scoped GITEA_ACCESS_TOKEN. GitWorktrees already neutralizes the
file; only its stated reason changes, and it is now a confidentiality boundary.
The port-to-opencode skill taught {file:.secrets/} as the preferred pattern, so it is
rewritten to teach the central store and to say why we moved. .gitignore keeps the
.secrets/ line as a backstop against habit.
Includes the wiki pointer, which also carries the CB-559 config-reload correction.
14 lines
593 B
Plaintext
14 lines
593 B
Plaintext
# No secret belongs in this repo any more: every credential lives in one shell-level store
|
|
# (${SHARED_ENV}/tools/secrets.sh), and opencode.json reads it as {env:...}. This line stays as a
|
|
# backstop, so a workspace-scoped copy that someone re-creates by habit still cannot be committed.
|
|
.secrets/
|
|
|
|
# Settings backups inherit the env block — and secrets with it.
|
|
.claude/settings.local.json.bak*
|
|
|
|
# Daemon runtime artefacts. bridged appends its log wherever it is launched from, so both the
|
|
# repo root and bridged/ collect one; neither belongs in git.
|
|
bridged.out
|
|
bridged/bridged.out
|
|
logs/
|