Skip to content

Migrate and retire GitHub-secret authorization desired sets #2182

Description

@shiny-code-bot

Objective

Import, parity-check, cut over, and retire protected GitHub-secret managed authorization desired sets without changing decisions unexpectedly or losing recovery.

Current Status

State: Paused and blocked. The August 21, 2026 direction retains GitHub desired-set retirement as necessary group 7 deletion work, but it is not part of the active #2204#2177 phase.

Do not migrate desired sets, mutable reusable identities, repository secrets, or workflow selectors during the active milestone. Existing inventory evidence remains valid.

Resume trigger: DB-native administration/recovery prerequisites and #2177 are complete, and the owner selects this migration as a later bounded phase.

Scope

  • Inventory every protected LAUNCHPLANE_AUTHZ_*_MANAGED_SET_JSON input and exact workflow owner.
  • Import desired sets into DB-native drafts with source digest/provenance and no immediate authority change.
  • Compare old and new policy decisions across principals, actions, products, contexts, instances, workflows, and negative cases.
  • Exercise rollback, final-admin recovery, GitHub outage, secret loss, and provider-loss scenarios.
  • Cut routine administration to Launchplane API/UI only after parity and recovery gates pass.
  • Remove or disable routine workflow selectors and delete obsolete desired-set secrets after verified cutover.
  • Retain only the explicitly accepted bootstrap/break-glass transport and document its bounded capability.

Acceptance Criteria

  • Every current managed set has an exact DB-native import and decision-parity report.
  • No product repository owns or stores Launchplane permission desired state.
  • GitHub secret loss after cutover does not affect active authority or routine administration.
  • Rollback and bounded recovery are tested before any secret/workflow retirement.
  • Obsolete workflows, inputs, docs, tests, and secret references are removed rather than left as a second authority path.

Finish Line

Routine Launchplane authorization administration and desired state are entirely DB-native; GitHub retains only identity and the explicitly reviewed bootstrap/break-glass transport.

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:blockedPlan is blocked

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions