Skip to content

Add Octo STS policy for livegrep.chaindag.dev indexer#117

Merged
jml merged 1 commit into
chainguard-images:mainfrom
jml:livegrep-indexer-sts
May 12, 2026
Merged

Add Octo STS policy for livegrep.chaindag.dev indexer#117
jml merged 1 commit into
chainguard-images:mainfrom
jml:livegrep-indexer-sts

Conversation

@jml
Copy link
Copy Markdown
Contributor

@jml jml commented May 12, 2026

What

Add the Octo STS policy that lets the livegrep.chaindag.dev indexer mint a read-only GitHub token for this org.

Why

We are expanding livegrep beyond chainguard-dev to cover every org in the Chainguard enterprise account. The indexer authenticates per-org via Octo STS, so each org needs its own policy granting the indexer GCP service account contents: read + metadata: read.

Notes

  • Subject is the unique ID of livegrep@chaindag.iam.gserviceaccount.com.
  • The same policy is already deployed in chainguard-dev/.github.
  • The indexer is defined in env/chaindag.dev/iac/livegrep.tf in chainguard-dev/mono; expanding indexer_orgs to include this org is a follow-up there.

@jml jml enabled auto-merge (squash) May 12, 2026 18:10
@jml jml merged commit 04d0588 into chainguard-images:main May 12, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants