docs: lead decision 68, a service account owns the Vikunja bots (sage)

Darkwing's row 38 labels probe on the pinned 2.7.0 image: a bot created
from the owner's account reads and attaches every label that account
created, in any project (upstream #3592). Bots owned by svc-<business>,
an account with no labels and no shares, see only labels on the shared
project's tasks. The runbook now creates the bots and mints and revokes
their tokens as svc-$BIZ; the owner keeps the project and the shares.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-08 17:13:51 -05:00
co-authored by Claude Opus 5.5
parent d228b03298
commit bc33faa38f
2 changed files with 105 additions and 29 deletions
+34
View File
@@ -1196,3 +1196,37 @@ which stay with him. Each item names who decided it and what happened.
proposed Sage as PM and Darkwing as Lead (the PRD's CTO role).
That is the slice 1 brief's staffing already: PM held by Sage,
CTO by Darkwing. No row changes.
68. **A per-business service account owns the Vikunja bots
(2026-10-08).** Source: Darkwing's row 38 probe record,
`agents/darkwing/work/slice1-s3/probes.md` section L, on the
pinned 2.7.0 image in a scratch container. Decision 66 made the
labels probe a precondition for the estate instance, and it failed
with the runbook as written.
- In 2.7.0 a bot reads and attaches every label its owning account
created, in any project. Upstream treats that as intended
(`pkg/models/label_test.go`, #3592). A PM bot created from the
owner's account and shared only into mosaic-stack listed the
owner's Launchpad, personal and unattached labels, and attached
two of them to a mosaic-stack task (201). On the estate instance,
bots under Jason's account would see every Launchpad, personal
and system label.
- Control: the same bot owned by `svc-mosaic-stack`, an account
with no labels and no shares, saw only labels on mosaic-stack
tasks and got 403 on the others. The project owner can share a
bot that another account owns. Only the owning account can mint
its token (the owner got 404, code 1005).
- Ruling: each business gets a service account `svc-<business>`,
not Jason's. It creates that business's five bots and mints and
revokes their tokens. It owns no labels, projects or other bots,
and nobody shares a project with it. Jason's account still owns
the project and makes the shares. The runbook's sections 2 to 5
say this now.
- S3's broker also attaches only the label ids the business file
lists, so a label that later becomes visible can't be attached.
This is a second guard and doesn't replace the first.
- Still to probe before Jason runs section 3: whether `svc` can
revoke a bot's token with `DELETE /tokens/{id}`, as the rotation
step now says. Darkwing adds it to the record.
- T236 has to provide `svc-mosaic-stack` on the estate instance.
Its operator creates it with `vikunja user create`, unless the
instance allows registration. Sent to Mos.