Repository navigation
ci: remove the preview-deploy workflows and the credential they carry - #378
Conversation
|
Gate output, run against a clean export of this branch and, where a before/after matters, against No file references the deleted workflows: The remaining hit is two historical fingerprints keyed to commit Nothing pushes to a registry any more: On detect-secrets 1.5.0, the version pinned in
One thing this does not do: |
|
Closing: opened prematurely and not ready for review. The changes here are being reworked and will come back as their own pull requests. |
akshitpatel1732
left a comment
There was a problem hiding this comment.
Is deleting these three workflow files the only way forward?
Hisotry for pr.preview-deploy.yml runs show most jobs being skipped or being aborted with the exception of one failing job (run by me). The step where it failed includes Alembic migrations which might be the cause as at that time, as main had two alembic heads (now resolved).
Can we preserve these workflow files by hard-disabling them, until a solution is devised to make them work while aligning with our stance on security?
Opinions/arguments are welcome. Thanks.
akshitpatel1732
left a comment
There was a problem hiding this comment.
Following up on the disable-vs-delete question: disabling the trigger wouldn't actually get us the security benefit, since the hardcoded credential would still sit in a live, tracked file that detect-secrets/Gitleaks would keep flagging - to fix that properly we'd end up rewriting most of the workflow anyway. Given that, and that this is fully recoverable from git history whenever someone has time to rebuild it with real secret-wiring, going with deletion as proposed.
Approving.
|
Hi @sh4mbhavi, could you please resolve the merge conflict so this can be merged safely? Thanks. |
The deploy job cannot start. `docker-compose.yml:39` requires `POSTGRES_PASSWORD` -- made required upstream in `f7981302` -- and the workflow sets it nowhere in its 430 lines, so `docker compose up -d db redis opa` at line 240 aborts. While it sits there unable to run, lines 273 and 322 carry the published default database password inside a `postgresql+asyncpg://` URL on a `docker run` command line. detect-secrets 1.5.0 reports it as Basic Auth Credentials at line 267 and `.secrets.baseline` allowlists nothing. The build job in front of it still ran, pushing three mutable `pr-<number>` tags to GHCR on every trigger, so the stack burned CI minutes and published images for an environment that could never come up. `pr.preview-teardown.yml` and `pr.preview-instructions.yml` exist only to tear down and to advertise that environment, so all three go together. Three README paragraphs described the machinery being deleted: the project overview called the monorepo an enabler of "rapid automated deployments to the cloud", the Docker Builds section said production images are pushed to Docker Hub and to GCP Artifact Registry, and Contact & Support routed production deployment queries to a DevOps lead managing GCP integration. After this deletion `git grep -rn "ghcr.io\|build-push-action\|docker push" .github/workflows/` is empty, `ci.grype.yml` already records that its image build was replaced by a directory scan because Docker Hub is no longer configured, and the only workflow still referencing GCP, `ops.collector.yml`, is hard-disabled because it used a long-lived service-account key. The credential remains in git history, so it still has to be rotated. Deleting the file removes one place it is stored, not the exposure.
`.github/actionlint.yaml` carried a per-file ignore block for `pr.preview-deploy.yml`, and `.secrets.baseline` allowlisted the Basic Auth Credentials finding at its line 267. Both were added on `main` after this branch was cut, and both point at a file this branch deletes. The baseline entry in particular allowlists the very credential this change removes, so it must not survive the deletion. `git grep -n "pr\.preview"` is empty again after this.
82aec50 to
97b3f87
Compare
akshitpatel1732
left a comment
There was a problem hiding this comment.
Verified the resolved diff directly - clean, just the deletions plus the README correction, and the actionlint/secrets-baseline cleanup for the two stale references that landed on main after this branch was cut. Nothing extra came along. Approving.
7be9f6a
into
Hardhat-Enterprises:main
Summary
Deletes
.github/workflows/pr.preview-deploy.yml,pr.preview-teardown.ymlandpr.preview-instructions.yml, and corrects the three README paragraphs that described them.Type of Change
Affected Components
/.github/workflows- [x]/docsMotivation
The deploy job cannot start.
docker-compose.yml:39requiresPOSTGRES_PASSWORD(
${POSTGRES_PASSWORD:?...}, made required upstream in f798130 on 2026-08-16) and the workflowsets it nowhere in 430 lines, so
docker compose up -d db redis opaat line 240 aborts. While itsits there unable to run, lines 273 and 322 carry the published default database password inside a
postgresql+asyncpg://URL on adocker runcommand line, with no allowlist pragma. detect-secrets1.5.0 reports it as Basic Auth Credentials at line 267 and
.secrets.baselinedoes not allowlist it.Testing Done
git grep -n "pr\.preview"now returnsnothing, and
git grep -rn "preview-deploy"returns only the stale.gitleaks-baseline.jsonfingerprints, which point at
.github/workflows/preview-deploy.yml, a path that no longer exists.Nothing in the repository depends on them.
Security Considerations
Removes a plaintext database credential from a tracked file. The same literal is printed at
docs/GETTING_STARTED.md:166, so this rotates nothing; it removes one place the value is stored.The same default credential also remains in git history, so an administrator must rotate it
regardless -- deletion at HEAD is not remediation.
Breaking Changes
deploy-preview,deploy-preview-m365andteardown-previewlabels stop havingany effect. A required status check named after one of these must be removed by an administrator.
Rollback Plan
git log --diff-filter=D -- .github/workflows/pr.preview-deploy.ymlrecovers the original.
Caveat (GRC-D03)
Demonstrates policy-decision correctness against fixtures. No live tenant has been
collected, so this is not evidence of any organisation's control posture.