Stop managing retired Ceapex PAT - #17413
Conversation
Remove dn-bot-ceapex-package-r from the EngKeyVault Secret Manager manifest now that OneLoc consumers have migrated to workload identity federation.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 42b6e46d-b9c0-4558-856d-1d1bdb50609d
There was a problem hiding this comment.
Pull request overview
Stops managing (and therefore rotating) the retired Ceapex packaging PAT by removing dn-bot-ceapex-package-r from the EngKeyVault Secret Manager manifest, aligning with the move to workload identity federation for audited OneLoc consumers.
Changes:
- Removed the
dn-bot-ceapex-package-rAzure DevOps access token secret definition from the EngKeyVault manifest. - Eliminated the Secret Manager-managed rotation path for the retired Ceapex packaging PAT.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Audit found that Confirmed evidence:
The EngKeyVault secret was rotated on 2026-08-26, remains enabled, expires on 2026-08-29, and is scheduled for another rotation on 2026-08-27. Do not merge this PR or remove the variable-group values until these consumers are migrated or explicitly retired and post-migration runs succeed. |
Summary
dn-bot-ceapex-package-rfrom the EngKeyVault Secret Manager manifestThe shared OneLoc template's explicit PAT input remains available for compatibility; removal from variable group 103 and EngKeyVault is tracked as operational cleanup.
AB#10151