From 71036cb3f4911613f4a54648e79f48ddc78d00f7 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 22 Jun 2026 19:54:53 -0400 Subject: [PATCH] chore(security-review): bring confluence-doc online in the nightly coordinator (#42) confluence-doc is provisioned (OAuth 2.0 service-account creds in ~/secrev.env + PAGE_MAP_FILE from the live IT space). Drop it from COORDINATOR_SKIP_ROLES (now just aws-posture) and add Environment=PAGE_MAP_FILE. Verified live on the box: 'Confluence API: oauth auth ready', 21 recommend-only doc gaps reported (D7, no writes). aws-posture stays skipped (IAM/step-ca not stood up). --- security-review/systemd/sea-haven-checkers.service | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/security-review/systemd/sea-haven-checkers.service b/security-review/systemd/sea-haven-checkers.service index ada9a99..93dc6f1 100644 --- a/security-review/systemd/sea-haven-checkers.service +++ b/security-review/systemd/sea-haven-checkers.service @@ -18,8 +18,11 @@ # # COORDINATOR_SKIP_ROLES excludes roles whose creds are NOT provisioned: # - aws-posture needs IAM Roles Anywhere / step-ca (not provisioned) -# - confluence-doc needs the confluence-bot Atlassian token (not provisioned) -# Remove a name here once its credential is provisioned to bring that checker online. +# confluence-doc is ONLINE (2026-06-22): authenticates via the OAuth 2.0 +# client-credentials service account in ~/secrev.env (CONFLUENCE_BASE_URL + +# CONFLUENCE_OAUTH_CLIENT_ID/_SECRET); PAGE_MAP_FILE points at the IT page-ID map +# generated from the live space. Remove a name from the skip list once its +# credential is provisioned to bring that checker online. [Unit] Description=Sea Haven agent-team Plane-1 nightly checker coordinator @@ -33,7 +36,10 @@ WorkingDirectory=/home/adam/orchestrator/security-review EnvironmentFile=-/home/adam/secrev.env EnvironmentFile=-/home/adam/orchestrator/.env Environment=GH_ORG=Sea-Haven-Industries -Environment=COORDINATOR_SKIP_ROLES=aws-posture,confluence-doc +Environment=COORDINATOR_SKIP_ROLES=aws-posture +# IT page-ID map for confluence-doc (generated from the live space; regenerate +# periodically as pages change). +Environment=PAGE_MAP_FILE=/home/adam/confluence-page-map.json # Tune the shared ceiling without editing the script (uncomment to override): # Environment=TOTAL_BUDGET_USD=120 # Environment=MAX_CYCLE_NIGHTS=4