Skip to content

Commit 2591cc2

Browse files
committed
docs: document portable workflow sync authentication
1 parent af565b1 commit 2591cc2

1 file changed

Lines changed: 32 additions & 0 deletions

File tree

‎docs/cross-repository-automation.md‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -112,3 +112,35 @@ The initial production validation confirmed:
112112
- `LibreCodeCoop/extract` can be checked out and updated;
113113
- managed workflows can be adopted into the lock file;
114114
- a subsequent synchronization with current hashes creates no PR.
115+
116+
117+
## Portable consumer authentication
118+
119+
The installed workflow updater does not infer authentication from the consumer's
120+
organization name. Consumers select an explicit repository variable:
121+
122+
\`WORKFLOW_SYNC_AUTH_MODE\`
123+
124+
Supported values:
125+
126+
- \`librecode-app\` — default for existing LibreCode-managed repositories. Uses
127+
\`LIBRECODE_WORKFLOW_APP_ID\` and \`LIBRECODE_WORKFLOW_APP_PRIVATE_KEY\`.
128+
- \`github-app\` — uses a consumer-owned GitHub App configured through
129+
\`WORKFLOW_SYNC_APP_ID\` and \`WORKFLOW_SYNC_APP_PRIVATE_KEY\`.
130+
- \`token\` — uses a consumer-owned repository-scoped credential stored as
131+
\`WORKFLOW_SYNC_TOKEN\`.
132+
- \`github-token\` — uses the workflow's built-in \`GITHUB_TOKEN\`.
133+
134+
A consumer-owned GitHub App is preferred for independent projects because it
135+
keeps credentials under the consumer's control while still allowing generated
136+
pull requests to trigger normal repository automation.
137+
138+
The \`github-token\` mode is intentionally explicit. GitHub suppresses workflow
139+
runs caused by most events created with the repository \`GITHUB_TOKEN\`, which
140+
means a pull request created through that mode may not trigger the consumer's
141+
normal pull-request CI. Use it only when that limitation is acceptable or when
142+
another mechanism explicitly triggers validation.
143+
144+
For GitHub App credentials, request only the repository permissions needed by
145+
the updater: Contents write, Pull requests write and Workflows write. Do not
146+
install or share the LibreCode GitHub App/private key with external consumers.

0 commit comments

Comments
 (0)