deploy keys: no way to grant the scope that already exists #22

closed cmc opened this on 2026-08-24 03:03 UTC · keys roadmap

Discussion

cmc 2026-08-24 03:03 UTC

The policy layer understands deploy:<owner/name>:ro|rw key scopes — but no command can create such a key: keys add only accepts full|git. Close the gap: repo deploy-key add <owner/name> [--rw] < key.pub (repo admin), listed/removed per repo. Small, and unblocks per-repo CI checkout credentials.

cmc 2026-08-24 15:44 UTC

Shipped: repo deploy-key add/list/remove, scope bound to the repo ID so bindings survive rename/transfer; authorization by binding alone, never inherited; e2e covers ro/rw, cross-repo denial, control denial, transfer survival, removal.