Skip to content

DRU-761 -- Use the manager's GitHub App for API calls, Git credentials, and account links - #844

Merged
czpython merged 1 commit into
mainfrom
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials
Oct 8, 2026
Merged

czpython merged 1 commit into
mainfrom
paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials

Conversation

@czpython

@czpython czpython commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Druks consumes the Cloud GitHub App through the manager's relay. The self-hosted path does not change, and neither does the provider code: a managed GitHub card differs from a self-hosted one in a URL and a key.

  • [manager] replaces managed_by in druks.toml: name, jwks_url, issuer, audience, instance, services, and the secret file manager.token. The table loads complete or not at all, and a managed_by key or a manager.token key in TOML refuses to start.
  • manager.services names the services the manager manages. Each one's table holds the url where the manager answers its calls, the plain Settings fields, and the secret files the table gives; any other key is a fact. The GitHub table holds url, app_id, client_id, and slug, and the file services.github.private_key holds the instance's own key. The startup sync keeps the facts a card learned since, such as GitHub's installations. A service that druks.toml configures with its own secrets, such as WAHA, keeps its own verifier, OAuth client, and credentials; is_managed() names the first case and is_configured() the second.
  • GitHubClient signs the App's calls with the card's key at the card's url: GitHub for a self-hosted App, the relay for a managed one, where the manager verifies the instance's signature. It mints each installation token there, keeps it in Redis until GitHub's expiry as the OAuth tokens are kept, drops it on a 401 for one fresh-token retry, and calls GitHub with it. The installation directory stays GitHub's own routes, /app/installations and /orgs/{org}/installation, which the relay serves for the installations this Druks owns. Git and Drukbox credentials go through the same token_for_repo.
  • A managed service exchanges and refreshes at the relay's oauth/token: every token request carries the manager token and no client secret, the state begins with the manager's instance name for this Druks, and the redirect is the manager's callback. The callback passes installation_id into the exchange and records the installed accounts on the card before it stores the grant. Personal grants stay in Druks.
  • Webhook.respond() verifies a managed service's forwarded event with the manager's JWT in X-Druks-Signature (audience, expiry, delivery id, body SHA-256) instead of the provider's own check. Delivery ids and duplicate protection do not change.
  • The service wire carries installUrl, the provider's install page from the service's get_install_endpoint(), or the sign-in door for a managed service, since the manager binds the installation there. The card shows Install for it and lists the installed accounts; it no longer names GitHub.
  • AGENTS.md: a managed service differs from a self-hosted one only in configuration.

Deploy order: the portal's [services.github] entry needs an image with this change, a relay that verifies the instance's key, and a relay that serves GitHub's installation directory routes.

@mintlify

mintlify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
druks 🟢 Ready View Preview Oct 8, 2026, 8:21 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from abaae9e to 23815be Compare October 6, 2026 19:21
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 23815be to 26ba23b Compare October 7, 2026 05:29
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 26ba23b to b3244b9 Compare October 7, 2026 06:02
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from b3244b9 to bd2d058 Compare October 7, 2026 07:00
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from bd2d058 to 53c0867 Compare October 7, 2026 07:05
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 53c0867 to 5d7cdcb Compare October 7, 2026 07:13
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 5d7cdcb to adf5c5a Compare October 7, 2026 17:01
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from adf5c5a to c7511b4 Compare October 7, 2026 17:16
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from c7511b4 to a1b9e75 Compare October 7, 2026 17:24
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from a1b9e75 to 1e06e6d Compare October 7, 2026 17:33
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 1e06e6d to 95ae124 Compare October 7, 2026 19:43
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 95ae124 to 5ab1f23 Compare October 7, 2026 19:54
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 5ab1f23 to b85ac0b Compare October 7, 2026 20:04
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from b85ac0b to 798d249 Compare October 8, 2026 08:07
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 798d249 to 4409b6b Compare October 8, 2026 08:12
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 4409b6b to 07c0a25 Compare October 8, 2026 08:15
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from 07c0a25 to e37ee39 Compare October 8, 2026 08:18
@czpython
czpython force-pushed the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch from e37ee39 to 7328152 Compare October 8, 2026 08:21
@czpython
czpython enabled auto-merge (squash) October 8, 2026 08:23
@czpython
czpython merged commit c6f7e35 into main Oct 8, 2026
5 checks passed
@czpython
czpython deleted the paulo/dru-761-druks-use-the-cloud-github-app-for-api-calls-git-credentials branch October 8, 2026 08:27

This branch was successfully deployed

1 active deployment
staging - docs — 73281523 Deployed Oct 8, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant