Security: live Gitea runner registration token committed in cleartext in spikersoft-infrastructure #916

Closed
opened 2026-08-05 13:58:41 +00:00 by spikerj · 0 comments
Owner

spikersoft-infrastructure/gitea-act-runner/command-line-version.txt contains a live runner registration token in cleartext (found during the 2026-08-05 runner audit).

Per the secrets-in-openbao rule this should never be in git. Fix:

  1. Rotate the token in Gitea > Site Administration > Actions > Runners (invalidate the committed one).
  2. Remove the token from the file (or delete the file; the stack header already documents passing GITEA_RUNNER_REGISTRATION_TOKEN through the environment).
  3. Store the replacement in OpenBao under secret/ci/spikersoft-infrastructure/... and note it in the provisioning script per the runbook.

Note: token is only needed for FRESH registrations — existing runners keep their .runner identity, so rotation does not disrupt the fleet.

`spikersoft-infrastructure/gitea-act-runner/command-line-version.txt` contains a live runner registration token in cleartext (found during the 2026-08-05 runner audit). Per the secrets-in-openbao rule this should never be in git. Fix: 1. Rotate the token in Gitea > Site Administration > Actions > Runners (invalidate the committed one). 2. Remove the token from the file (or delete the file; the stack header already documents passing `GITEA_RUNNER_REGISTRATION_TOKEN` through the environment). 3. Store the replacement in OpenBao under `secret/ci/spikersoft-infrastructure/...` and note it in the provisioning script per the runbook. Note: token is only needed for FRESH registrations — existing runners keep their `.runner` identity, so rotation does not disrupt the fleet.
Sign in to join this conversation.