You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Namespace where the orchestrator ServiceAccount actually lives.
334
+
namespace: ${ORCHESTRATOR_NAMESPACE}
332
335
roleRef:
333
336
kind: Role
334
337
name: github-app-playground-ephemeral-spawner
@@ -339,4 +342,4 @@ Without these verbs, every scale-up attempt yields `dispatch_reason=ephemeral-sp
339
342
340
343
### `daemon-secrets` Secret
341
344
342
-
Spawned ephemeral daemon Pods receive their configuration via `envFrom: secretRef: daemon-secrets`. Create this Secret once in `EPHEMERAL_DAEMON_NAMESPACE` with the GitHub App credentials used by the orchestrator (so the daemon can reuse the installation-token path), Claude provider keys, and the data-layer URLs (`DATABASE_URL`, `VALKEY_URL`). See [DAEMON.md](DAEMON.md) for the full key list.
345
+
Spawned ephemeral daemon Pods receive their configuration via `envFrom: secretRef: daemon-secrets`. Create this Secret once in `EPHEMERAL_DAEMON_NAMESPACE` with only the daemon runtime values it needs — `DAEMON_AUTH_TOKEN`, Claude provider keys, and the daemon-side data-layer URLs (`DATABASE_URL`, `VALKEY_URL`). Do **not** copy GitHub App private-key material into this Secret: the orchestrator mints installation tokens and hands them to the daemon per job, so expanding the blast radius to every ephemeral Pod is unnecessary. See [DAEMON.md](DAEMON.md) for the full key list.
0 commit comments