Skip to content

ci: remove the preview-deploy workflows and the credential they carry - #378

Merged
akshitpatel1732 merged 2 commits into
Hardhat-Enterprises:mainfrom
sh4mbhavi:hotfix/remove-dead-preview-deploy
Sep 21, 2026
Merged

akshitpatel1732 merged 2 commits into
Hardhat-Enterprises:mainfrom
sh4mbhavi:hotfix/remove-dead-preview-deploy

Conversation

@sh4mbhavi

@sh4mbhavi sh4mbhavi commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Deletes .github/workflows/pr.preview-deploy.yml, pr.preview-teardown.yml and
pr.preview-instructions.yml, and corrects the three README paragraphs that described them.

Type of Change

  • Security - [x] CI/CD / infrastructure - [x] Documentation

Affected Components

  • /.github/workflows - [x] /docs

Motivation

The deploy job cannot start. docker-compose.yml:39 requires POSTGRES_PASSWORD
(${POSTGRES_PASSWORD:?...}, made required upstream in f798130 on 2026-08-16) and the workflow
sets it nowhere in 430 lines, so docker compose up -d db redis opa at line 240 aborts. While it
sits there unable to run, lines 273 and 322 carry the published default database password inside a
postgresql+asyncpg:// URL on a docker run command line, with no allowlist pragma. detect-secrets
1.5.0 reports it as Basic Auth Credentials at line 267 and .secrets.baseline does not allowlist it.

Testing Done

  • No tests required, because this is a deletion. git grep -n "pr\.preview" now returns
    nothing, and git grep -rn "preview-deploy" returns only the stale .gitleaks-baseline.json
    fingerprints, which point at .github/workflows/preview-deploy.yml, a path that no longer exists.
    Nothing in the repository depends on them.

Security Considerations

Removes a plaintext database credential from a tracked file. The same literal is printed at
docs/GETTING_STARTED.md:166, so this rotates nothing; it removes one place the value is stored.
The same default credential also remains in git history, so an administrator must rotate it
regardless -- deletion at HEAD is not remediation.

Breaking Changes

  • Yes. The deploy-preview, deploy-preview-m365 and teardown-preview labels stop having
    any effect. A required status check named after one of these must be removed by an administrator.

Rollback Plan

  • Revert is sufficient. git log --diff-filter=D -- .github/workflows/pr.preview-deploy.yml
    recovers the original.

Caveat (GRC-D03)

Demonstrates policy-decision correctness against fixtures. No live tenant has been
collected, so this is not evidence of any organisation's control posture.

@sh4mbhavi
sh4mbhavi requested a review from a team as a code owner September 8, 2026 06:31
@sh4mbhavi

Copy link
Copy Markdown
Contributor Author

Gate output, run against a clean export of this branch and, where a before/after matters, against
main (5bf4ea8).

No file references the deleted workflows:

$ git grep -n "pr\.preview"
(exit 1, no output)

$ git grep -rl "preview-deploy"
.gitleaks-baseline.json

The remaining hit is two historical fingerprints keyed to commit f5f13553, and they name
.github/workflows/preview-deploy.yml -- a path without the pr. prefix that has not existed since
the file was renamed. They are stale either way.

Nothing pushes to a registry any more:

$ git grep -rn "ghcr.io\|build-push-action\|docker push" .github/workflows/
(exit 1, no output)

On main the same command returns 11 hits, all in pr.preview-deploy.yml.

detect-secrets 1.5.0, the version pinned in .pre-commit-config.yaml:

# on main
$ detect-secrets scan .github/workflows/pr.preview-deploy.yml
[('.github/workflows/pr.preview-deploy.yml', 267, 'Basic Auth Credentials')]

# on this branch
$ detect-secrets scan .github/workflows/
files flagged: NONE

.secrets.baseline on main has "results": {}, so nothing was suppressing that finding.

One thing this does not do: pre-commit run detect-secrets --all-files still fails on main and
still fails after this change, on 15 findings in .gitleaks-baseline.json and
backend-api/app/db/seed_dev.py that this pull request does not touch. The claim here is only the
narrow one -- line 267 is gone.

@sh4mbhavi

Copy link
Copy Markdown
Contributor Author

Closing: opened prematurely and not ready for review. The changes here are being reworked and will come back as their own pull requests.

@sh4mbhavi sh4mbhavi closed this Sep 8, 2026
@sh4mbhavi sh4mbhavi reopened this Sep 8, 2026
@github-actions github-actions Bot added github_actions GitHub Actions related area: ci-cd Changes under /.github area: root Loose root-level files or IDE config area: multi Touches more than one work area size/XL > 500 lines changed, or > 30 files changed labels Sep 8, 2026

@akshitpatel1732 akshitpatel1732 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is deleting these three workflow files the only way forward?
Hisotry for pr.preview-deploy.yml runs show most jobs being skipped or being aborted with the exception of one failing job (run by me). The step where it failed includes Alembic migrations which might be the cause as at that time, as main had two alembic heads (now resolved).

Can we preserve these workflow files by hard-disabling them, until a solution is devised to make them work while aligning with our stance on security?

Opinions/arguments are welcome. Thanks.

@akshitpatel1732 akshitpatel1732 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Following up on the disable-vs-delete question: disabling the trigger wouldn't actually get us the security benefit, since the hardcoded credential would still sit in a live, tracked file that detect-secrets/Gitleaks would keep flagging - to fix that properly we'd end up rewriting most of the workflow anyway. Given that, and that this is fully recoverable from git history whenever someone has time to rebuild it with real secret-wiring, going with deletion as proposed.

Approving.

@akshitpatel1732

Copy link
Copy Markdown
Contributor

Hi @sh4mbhavi, could you please resolve the merge conflict so this can be merged safely? Thanks.

The deploy job cannot start. `docker-compose.yml:39` requires
`POSTGRES_PASSWORD` -- made required upstream in `f7981302` -- and the workflow
sets it nowhere in its 430 lines, so `docker compose up -d db redis opa` at
line 240 aborts. While it sits there unable to run, lines 273 and 322 carry the
published default database password inside a `postgresql+asyncpg://` URL on a
`docker run` command line. detect-secrets 1.5.0 reports it as Basic Auth
Credentials at line 267 and `.secrets.baseline` allowlists nothing.

The build job in front of it still ran, pushing three mutable `pr-<number>`
tags to GHCR on every trigger, so the stack burned CI minutes and published
images for an environment that could never come up.

`pr.preview-teardown.yml` and `pr.preview-instructions.yml` exist only to tear
down and to advertise that environment, so all three go together.

Three README paragraphs described the machinery being deleted: the project
overview called the monorepo an enabler of "rapid automated deployments to the
cloud", the Docker Builds section said production images are pushed to Docker
Hub and to GCP Artifact Registry, and Contact & Support routed production
deployment queries to a DevOps lead managing GCP integration. After this
deletion `git grep -rn "ghcr.io\|build-push-action\|docker push"
.github/workflows/` is empty, `ci.grype.yml` already records that its image
build was replaced by a directory scan because Docker Hub is no longer
configured, and the only workflow still referencing GCP, `ops.collector.yml`,
is hard-disabled because it used a long-lived service-account key.

The credential remains in git history, so it still has to be rotated. Deleting
the file removes one place it is stored, not the exposure.
`.github/actionlint.yaml` carried a per-file ignore block for
`pr.preview-deploy.yml`, and `.secrets.baseline` allowlisted the
Basic Auth Credentials finding at its line 267. Both were added on
`main` after this branch was cut, and both point at a file this
branch deletes. The baseline entry in particular allowlists the very
credential this change removes, so it must not survive the deletion.

`git grep -n "pr\.preview"` is empty again after this.
@sh4mbhavi
sh4mbhavi force-pushed the hotfix/remove-dead-preview-deploy branch from 82aec50 to 97b3f87 Compare September 20, 2026 08:45
@github-actions github-actions Bot added the needs-review Author (or someone else) responded since the reviewer's last comment — needs another look label Sep 20, 2026

@akshitpatel1732 akshitpatel1732 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified the resolved diff directly - clean, just the deletions plus the README correction, and the actionlint/secrets-baseline cleanup for the two stale references that landed on main after this branch was cut. Nothing extra came along. Approving.

@akshitpatel1732
akshitpatel1732 merged commit 7be9f6a into Hardhat-Enterprises:main Sep 21, 2026
13 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd Changes under /.github area: multi Touches more than one work area area: root Loose root-level files or IDE config github_actions GitHub Actions related needs-review Author (or someone else) responded since the reviewer's last comment — needs another look size/XL > 500 lines changed, or > 30 files changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants