GitHub Repository Secrets Setup¶
This document describes every secret that must be configured in repository settings for Base Coat's GitHub Actions workflows to run correctly.
Navigate to: Settings → Secrets and variables → Actions → New repository secret
Bootstrap Audit Logging¶
The bootstrap script generates a structured audit log at .memory/bootstrap-audit.json with all checks, warnings, and errors found during setup. This log includes:
- Timestamp of bootstrap run
- Pass/fail counts for all validation checks
- Detailed check results (label, status, details)
- Warnings and errors lists for issue tracking
Creating GitHub issues for critical errors¶
Run with -CreateIssues flag to automatically open a GitHub issue when critical validation errors are found:
This is useful for team adoption: each bootstrap run can surface issues requiring attention without manual reporting. The -CreateIssues flag is disabled in -Silent mode (CI use) to avoid spam.
Required Secrets¶
Profile-driven bootstrap matrix¶
pwsh scripts/bootstrap.ps1 now evaluates required secrets and variables using
the onboarding profile contract (solo-dev, team-dev, regulated-team).
- Explicit override:
-OnboardingProfile <profile> - Contract-driven:
-OnboardingContractPath <path-to-contract-json> - Non-interactive CI mode:
-Silent(fails checks with exact remediation text)
Default profile resolution order:
-OnboardingProfileBASECOAT_ONBOARDING_PROFILE- Contract file profile (default
.github/basecoat-onboarding-profile.json) team-dev
| Profile | Workflow pack | Required secrets/variables surfaced by bootstrap |
|---|---|---|
solo-dev |
solo |
COPILOT_GITHUB_TOKEN |
team-dev |
team |
COPILOT_GITHUB_TOKEN, GH_AW_GITHUB_TOKEN (+ PRODUCTION_REPO_TOKEN when publish workflow exists; portal variables and GHCR_PULL_TOKEN when portal deploy workflow exists) |
regulated-team |
regulated |
COPILOT_GITHUB_TOKEN, GH_AW_GITHUB_TOKEN, GH_AW_GITHUB_MCP_SERVER_TOKEN (+ same workflow-conditional requirements as team-dev) |
Bootstrap output includes token rotation/expiration guidance and never writes plaintext secrets to repository files.
Portal deploy bootstrap order (staging)¶
Use this order to avoid mixed bootstrap/deploy failures:
- Run
pwsh scripts/bootstrap.ps1in the repo. - This is the correct bootstrap for BaseCoat repo operations and portal deploy readiness.
- Do not substitute
scripts/bootstrap-basecoat.ps1(consumer-repo adoption) orscripts/bootstrap-dashboard.ps1(adoption dashboard setup). - Keep Azure CLI logged in and rerun
pwsh scripts/bootstrap.ps1to auto-provision the portal OIDC app registration and repo variables when missing. - Set
GHCR_PULL_TOKENat repo scope orstagingenvironment scope. - Re-run
pwsh scripts/bootstrap.ps1and verify Phase 3 passes portal OIDC checks. - Trigger
.github/workflows/portal-deploy.yml.
The deploy workflow now fails fast in the Validate deployment secrets step when required portal variables are missing or malformed. The bootstrap script can auto-generate the Azure app registration, federated credential, and repo variables from the current Azure CLI session, but the GHCR pull token still requires a manually created PAT with read:packages and expiration set to 30 days or less.
COPILOT_GITHUB_TOKEN¶
Used by: issue-triage.lock.yml, code-review-agent.lock.yml,
security-analyst.lock.yml, retro-facilitator.lock.yml,
self-healing-ci.lock.yml, release-impact-advisor.lock.yml
Purpose: Authenticates the GitHub Agentic Workflow (gh-aw) agent containers. Without this secret the agentic lock-file workflows will fail to start.
How to create (recommended):
- Go to https://github.com/settings/personal-access-tokens/new
- Create a fine-grained PAT
- Set Resource owner to your user account
- Under Account permissions, set Copilot Requests →
Read - Set PAT expiration to 30 days or less
- Generate token and copy it immediately
- Run bootstrap script:
If you prefer manual UI setup, add the value as repository secret
COPILOT_GITHUB_TOKEN.
Rotation schedule: Rotate every 30 days. Set a calendar reminder. When rotating, generate a new token before the old one expires, update the secret, then revoke the old token.
GH_AW_GITHUB_TOKEN¶
Used by: All *.lock.yml agentic workflow files
Purpose: Grants the agentic workflow read access to repository contents
during agent execution (separate from COPILOT_GITHUB_TOKEN for least-privilege
isolation).
How to create: Use a separate token from COPILOT_GITHUB_TOKEN
(recommended). Name it basecoat-gh-aw and grant only the minimum
repository read permissions required. Set PAT expiration to 30 days or less.
GH_AW_GITHUB_MCP_SERVER_TOKEN¶
Used by: issue-triage.lock.yml, code-review-agent.lock.yml
Purpose: Authenticates the GitHub MCP server sidecar used by the gh-aw agent to call GitHub APIs from within the agent container.
How to create: A fine-grained PAT scoped to this repository with:
- Repository permissions: Issues (read/write), Pull requests (read/write), Contents (read)
- Name it
basecoat-mcp-server - Set PAT expiration to 30 days or less
STAGING_API_TOKEN¶
Used by: performance-baseline-pr-check.yml
Purpose: API token for the staging deployment used by k6 performance tests.
Note: This workflow is a pre-existing non-blocking failure when the staging
deployment is not provisioned. CI will report it as failing on every PR; this
does not block merges since branch protection is not enforced on main.
AZURE_CLIENT_ID¶
Used by: .github/workflows/portal-deploy.yml
Purpose: OIDC client ID for the portal deploy app registration.
AZURE_TENANT_ID¶
Used by: .github/workflows/portal-deploy.yml
Purpose: Entra tenant ID for Azure login.
AZURE_SUBSCRIPTION_ID¶
Used by: .github/workflows/portal-deploy.yml
Purpose: Target Azure subscription for portal staging deployment.
RBAC prerequisite for the identity referenced by AZURE_CLIENT_ID:
- Subscription scope access to create the target resource group (
Microsoft.Resources/subscriptions/resourcegroups/write), or the target group must be pre-provisioned. - Contributor (recommended) on the target portal resource group, or equivalent custom permissions including:
Microsoft.Resources/deployments/validate/actionMicrosoft.Resources/deployments/writeMicrosoft.ContainerRegistry/registries/*
PORTAL_POSTGRES_ADMIN_PASSWORD¶
Used by: .github/workflows/portal-deploy.yml
Purpose: Optional override for PostgreSQL admin password.
If omitted, portal/app/iac/main.bicep generates a secure password per deployment.
GHCR_PULL_TOKEN¶
Used by: .github/workflows/portal-deploy.yml
Purpose: Allows Container Apps runtime to pull private images from GHCR.
Required scope: read:packages
Set PAT expiration to 30 days or less and rotate monthly.
This is deployment/runtime specific (not just build-time): GITHUB_TOKEN can push images during workflow execution, but Azure Container Apps needs a separate credential to pull private GHCR images after deployment.
PRODUCTION_REPO_TOKEN¶
Used by: .github/workflows/publish-to-production.yml,
.github/workflows/docs-production.yml, .github/workflows/close-production-issues.yml
Purpose: Authorizes the publish-to-production workflow to push release
tags and the main branch from the source repository (YOUR-ORG/basecoat)
to the production repository (PRODUCTION-ORG/basecoat). Without this secret
the workflow fails immediately on any version tag push or manual dispatch.
How to create:
- Sign in to https://github.com as the production repository owner account
- Go to Settings → Developer settings → Fine-grained tokens → Generate new token
- Set Resource owner to
PRODUCTION-ORG - Set Repository access to
Only select repositories→PRODUCTION-ORG/basecoat - Under Repository permissions, grant:
- Contents: Read and write
- Administration: Read and write
- Workflows: Read and write
- Generate the token and copy it immediately
- Add it as a secret on the internal repository:
Verification:
Bootstrap check: Run pwsh scripts/bootstrap.ps1 — Phase 3 surfaces a
missing token with exact remediation steps. In -Silent (CI) mode, the check
emits a warning and skips interactive prompting.
Rotation schedule: Rotate when the production PAT expiration approaches. Set a calendar reminder matching the PAT expiration date. Generate a replacement token before the old one expires, update the secret, then revoke the old token.
Optional Secrets¶
SLACK_WEBHOOK_URL¶
Used by: Release notification step (if added in future)
Not currently wired up. Reserve the name if Slack integration is planned.
Optional Repository Variables (Agentic Workflow Model Overrides)¶
Set these under Settings → Secrets and variables → Actions → Variables when you need to override default gh-aw model selection:
GH_AW_MODEL_AGENT_COPILOT¶
Used by: Agent phase in issue-triage.lock.yml (and other gh-aw lock files
that reference the same variable)
Default when unset (issue triage): gpt-5-mini
GH_AW_MODEL_DETECTION_COPILOT¶
Used by: Threat-detection phase in issue-triage.lock.yml
Default when unset (issue triage): gpt-5-mini
Use only values supported by your Copilot subscription tier. If unsupported, the
workflow fails with 400 The requested model is not supported.
Validating Secrets¶
After setting all secrets, trigger a manual workflow run to confirm:
Check the Actions tab for green status on the triage job. If it fails with
secret not found, verify the secret name matches exactly (case-sensitive).