forgejo-mcp/scripts
Christoph Görn b63095f211
chore: 🔥 remove stale secrets/ + point at op1st-emea-b4mad as normative cosign pub
The op1st Tekton release pipeline signs with the cosign-signing-key
Secret in op1st-pipelines, provisioned upstream from op1st-emea-b4mad
GitOps. The in-repo secrets/cosign.pub diverged from that key (sha256
0c945708... vs 377836e4...) — verifying Tekton-signed releases against
the local key would fail. Local material was never the source of truth
and is now removed.

Removed:
- secrets/cosign.pub (stale, wrong key)
- secrets/cosign-signing-key.enc.yaml (SOPS-encrypted local copy, redundant with op1st-gitops)
- secrets/.gitkeep
- scripts/cosign-keygen.sh (helper for the removed local material)
- .gitignore allowlist for secrets/* (replaced with full secrets/ ignore)

Updated:
- README "Verifying Releases" → fetch cosign.pub from op1st-emea-b4mad
  at manifests/applications/op1st-pipelines-tokens/cosign-signing-key.pub.
  Both branch-tip and commit-pinned (8a3c55e5...) variants.
- ADR + runbook: operator precondition now references the op1st-emea-b4mad
  path instead of secrets/cosign.pub.

Refs: forgejo-mcp-a2y, forgejo-mcp-d4b
2026-05-25 13:35:31 +02:00
..
AGENTS.md chore: 🔧 add Claude Code agent team infrastructure for multi-agent workflows 2026-05-24 08:06:44 +02:00
openspec-journal-precompact-hook.sh chore: 🔧 add Claude Code agent team infrastructure for multi-agent workflows 2026-05-24 08:06:44 +02:00
openspec-journal.py chore: 🔧 add Claude Code agent team infrastructure for multi-agent workflows 2026-05-24 08:06:44 +02:00