Skip to content

Detect expired GitHub package credentials before deployment #82

Description

@teckedd-code2save

Failure observed

RentAWeekend's GitHub connector remained apparently usable while the dedicated GHCR PAT had expired on 21 Aug 2026. Deployment failed only at Validate Compose with ghcr.io/v2/: denied. Recovery required manually creating and pasting a new PAT.

Required connector behavior

  • Validate GHCR authentication and read:packages during connector setup.
  • Record token expiry when GitHub exposes it and warn before expiry.
  • Mark the connector degraded instead of connected when package access fails.
  • Run a harmless package-access probe before a deployment starts.
  • Provide guided credential rotation with exact missing scopes.
  • Distinguish Actions budget failures from registry authentication.
  • Preserve evidence, proposed action, verification and rollback in the deployment run.

Customer impact

Managed deploys fail late even though repository access looks healthy; operators fall back to raw Compose and can accidentally bypass GroundControl-managed component environments.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions