diff --git a/security-review/systemd/sea-haven-checkers.service b/security-review/systemd/sea-haven-checkers.service index ada9a99..93dc6f1 100644 --- a/security-review/systemd/sea-haven-checkers.service +++ b/security-review/systemd/sea-haven-checkers.service @@ -18,8 +18,11 @@ # # COORDINATOR_SKIP_ROLES excludes roles whose creds are NOT provisioned: # - aws-posture needs IAM Roles Anywhere / step-ca (not provisioned) -# - confluence-doc needs the confluence-bot Atlassian token (not provisioned) -# Remove a name here once its credential is provisioned to bring that checker online. +# confluence-doc is ONLINE (2026-06-22): authenticates via the OAuth 2.0 +# client-credentials service account in ~/secrev.env (CONFLUENCE_BASE_URL + +# CONFLUENCE_OAUTH_CLIENT_ID/_SECRET); PAGE_MAP_FILE points at the IT page-ID map +# generated from the live space. Remove a name from the skip list once its +# credential is provisioned to bring that checker online. [Unit] Description=Sea Haven agent-team Plane-1 nightly checker coordinator @@ -33,7 +36,10 @@ WorkingDirectory=/home/adam/orchestrator/security-review EnvironmentFile=-/home/adam/secrev.env EnvironmentFile=-/home/adam/orchestrator/.env Environment=GH_ORG=Sea-Haven-Industries -Environment=COORDINATOR_SKIP_ROLES=aws-posture,confluence-doc +Environment=COORDINATOR_SKIP_ROLES=aws-posture +# IT page-ID map for confluence-doc (generated from the live space; regenerate +# periodically as pages change). +Environment=PAGE_MAP_FILE=/home/adam/confluence-page-map.json # Tune the shared ceiling without editing the script (uncomment to override): # Environment=TOTAL_BUDGET_USD=120 # Environment=MAX_CYCLE_NIGHTS=4