Skip to content

[operator] Rotate OPS_GITHUB_TOKEN: GitHub Actions reads return 401 #665

Description

@i-xtsu-sixyou-ken-mei

Decision needed

Rotate OPS_GITHUB_TOKEN to a fine-grained PAT restricted to zapPilot/zapEngine, with only Actions: read (plus GitHub's mandatory repository metadata access). The configured credential is being rejected with HTTP 401; expiry/revocation is suspected, not yet proven. This is an operator credential action, not agent-backlog work.

Evidence

  • 09-30 13:49Z triage snapshot: GitHub provider returned 401 for all eight scheduled workflows; recent repository run history and deep inspections were unavailable.
  • The 09-30 14:45Z diagnostic snapshot supplied for this supplementary run likewise reported (401); ops-operator heartbeat was 545m against a 240m cadence. This historical snapshot was supplied by the operator, not independently replayed here.
  • Fresh ops_status force:true, generated 2026-09-30T15:01:53.712Z, confirms: GitHub recent main-branch run history failed (401) and no run history readable for any of 8 scheduled workflows: GitHub run history for track-record-snapshot.yml failed (401).
  • 09-24 comparison: all nine priority investigations had empty blockers and inspected coverage. This provider failure is new relative to that run.
  • Affected observations: github-actions:recent-runs/repository, github-actions:source-failure/adapter, and the missing github-actions:recent-failure/* stream. The durable DB heartbeat remains readable, but github-actions:workflow/ops-operator.yml cannot be deeply inspected. Earlier investigations also recorded GitHub 401 blockers for sentry:issues/alpha-etl (alpha-etl-daily-refresh.yml), sentry:stale-unresolved/analytics-engine (backtest-refresh.yml), and sentry:stale-unresolved/podcast-pipeline (distribution-snapshot.yml).
  • The separately configured backlog credential remains healthy: fresh ops_backlog force:true returned status ok, ready/working/blocked 2/0/0, not truncated. Local gh auth status verified active account i-xtsu-sixyou-ken-mei, and authenticated issue/run reads succeeded. Provider auth and backlog auth are separate.
  • Repository references: github.ts:102 reads the token; the unset-token branch at line 110 produces a different message and makes no request. env.manifest.mjs:407 declares the existing secret; README.md:197 documents Actions: read. No secret values are included.

Options

  1. Operator creates a fine-grained PAT for only zapPilot/zapEngine, Actions: read. The repository is public; no extra Contents permission is needed for public source reads.
  2. Operator updates the existing OPS_GITHUB_TOKEN key in Infisical prod. This is an existing manifest key, not a new environment variable.
  3. Restart/reconnect the local MCP session: scripts/ops-mcp.mjs loads Infisical with --environment prod on startup.
  4. For the remote dashboard, run Environment apply (env-apply.yml, workflow_dispatch, target=control-center-vercel); Vercel environment changes take effect on the next deployment.
  5. After the operator rotates/reconnects, the agent runs ops_status force:true and confirms both GitHub 401 source failures disappear and GitHub run history is readable. Until then, GitHub coverage remains unknown, not healthy. No rotation or deployment was performed in this supplementary run.

Fingerprint

triage:github-actions:OPS_GITHUB_TOKEN:401

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:control-centerScoped to apps/control-centeroperatorNeeds production credentials or a human decision; excluded from the agent backlog pool

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions