Repository navigation
DRU-761 -- Use the manager's GitHub App for API calls, Git credentials, and account links - #844
Merged
czpython merged 1 commit intoOct 8, 2026
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 6, 2026 19:21
abaae9e to
23815be
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 05:29
23815be to
26ba23b
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 06:02
26ba23b to
b3244b9
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 07:00
b3244b9 to
bd2d058
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 07:05
bd2d058 to
53c0867
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 07:13
53c0867 to
5d7cdcb
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 17:01
5d7cdcb to
adf5c5a
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 17:16
adf5c5a to
c7511b4
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 17:24
c7511b4 to
a1b9e75
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 17:33
a1b9e75 to
1e06e6d
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 19:43
1e06e6d to
95ae124
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 19:54
95ae124 to
5ab1f23
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 7, 2026 20:04
5ab1f23 to
b85ac0b
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 8, 2026 08:07
b85ac0b to
798d249
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 8, 2026 08:12
798d249 to
4409b6b
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 8, 2026 08:15
4409b6b to
07c0a25
Compare
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 8, 2026 08:18
07c0a25 to
e37ee39
Compare
…s, and account links
czpython
force-pushed
the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
from
October 8, 2026 08:21
e37ee39 to
7328152
Compare
czpython
enabled auto-merge (squash)
October 8, 2026 08:23
czpython
deleted the
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
branch
October 8, 2026 08:27
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Druks consumes the Cloud GitHub App through the manager's relay. The self-hosted path does not change, and neither does the provider code: a managed GitHub card differs from a self-hosted one in a URL and a key.
[manager]replacesmanaged_byindruks.toml:name,jwks_url,issuer,audience,instance,services, and the secret filemanager.token. The table loads complete or not at all, and amanaged_bykey or amanager.tokenkey in TOML refuses to start.manager.servicesnames the services the manager manages. Each one's table holds theurlwhere the manager answers its calls, the plainSettingsfields, and the secret files the table gives; any other key is a fact. The GitHub table holdsurl,app_id,client_id, andslug, and the fileservices.github.private_keyholds the instance's own key. The startup sync keeps the facts a card learned since, such as GitHub's installations. A service thatdruks.tomlconfigures with its own secrets, such as WAHA, keeps its own verifier, OAuth client, and credentials;is_managed()names the first case andis_configured()the second.GitHubClientsigns the App's calls with the card's key at the card'surl: GitHub for a self-hosted App, the relay for a managed one, where the manager verifies the instance's signature. It mints each installation token there, keeps it in Redis until GitHub's expiry as the OAuth tokens are kept, drops it on a 401 for one fresh-token retry, and calls GitHub with it. The installation directory stays GitHub's own routes,/app/installationsand/orgs/{org}/installation, which the relay serves for the installations this Druks owns. Git and Drukbox credentials go through the sametoken_for_repo.oauth/token: every token request carries the manager token and no client secret, the state begins with the manager'sinstancename for this Druks, and the redirect is the manager's callback. The callback passesinstallation_idinto the exchange and records the installed accounts on the card before it stores the grant. Personal grants stay in Druks.Webhook.respond()verifies a managed service's forwarded event with the manager's JWT inX-Druks-Signature(audience, expiry, delivery id, body SHA-256) instead of the provider's own check. Delivery ids and duplicate protection do not change.installUrl, the provider's install page from the service'sget_install_endpoint(), or the sign-in door for a managed service, since the manager binds the installation there. The card shows Install for it and lists the installed accounts; it no longer names GitHub.AGENTS.md: a managed service differs from a self-hosted one only in configuration.Deploy order: the portal's
[services.github]entry needs an image with this change, a relay that verifies the instance's key, and a relay that serves GitHub's installation directory routes.