Bind a GITEA_BOT_TOKEN on the ecomm deployment for patchwatch label provisioning #19

Open
opened 2026-06-11 07:56:55 +00:00 by ben.stull · 1 comment
Owner

The first flotilla-core deploy ecomm (v0.4.0, deploys.id=40, session 0024) ended green with one warning: patchwatch labels not provisioned — deployment 'ecomm' has no GITEA_BOT_TOKEN secret bound (the webhook/labels verbs need it). Non-blocking; deploys work without it. Resume context: bind via flotilla-core secret set ecomm GITEA_BOT_TOKEN <project>/<secret> once a bot token exists for this repo (cf. ohm-rfc-app's wiggleverse-ohm/ohm-rfc-app-gitea-bot-token); the wgl-gitea-admin TOKENS.md card maps the scopes.

The first `flotilla-core deploy ecomm` (v0.4.0, deploys.id=40, session 0024) ended green with one warning: *patchwatch labels not provisioned — deployment 'ecomm' has no GITEA_BOT_TOKEN secret bound* (the webhook/labels verbs need it). Non-blocking; deploys work without it. Resume context: bind via `flotilla-core secret set ecomm GITEA_BOT_TOKEN <project>/<secret>` once a bot token exists for this repo (cf. ohm-rfc-app's `wiggleverse-ohm/ohm-rfc-app-gitea-bot-token`); the wgl-gitea-admin TOKENS.md card maps the scopes.
ben.stull added the type/taskpriority/P3 labels 2026-06-11 07:56:55 +00:00
Author
Owner

Survives the pivot (session 0036). Patchwatch deploy-security tooling is direction-agnostic; the network service still needs dependency-advisory provisioning.

**Survives the pivot** (session 0036). Patchwatch deploy-security tooling is direction-agnostic; the network service still needs dependency-advisory provisioning.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiggleverse/wiggleverse-ecomm#19