Skip to content

chore(beads): name the tracker's remote by an alias, so this repo no longer says where it is - #415

Merged
GeiserX merged 1 commit into
mainfrom
chore/beads-tracker-alias
Oct 4, 2026
Merged

GeiserX merged 1 commit into
mainfrom
chore/beads-tracker-alias

Conversation

@GeiserX

@GeiserX GeiserX commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

.beads/config.yaml named the private server that holds this repo's issue tracker, and the agent instructions named the service it runs on. A public repo has no reason to say where that is.

The sync.remote line now names beads-tracker, an ssh alias that only the maintainer's machines resolve. The "Where the tracker syncs" section in the agent instructions now says "a private remote" and nothing more.

Nothing else changes. The tracker itself does not move, and syncing from the maintainer's machines works as before.

It also updates tests/test_ci_gates_report_what_they_checked.py, which named the old address, so it names the alias instead.

Summary by CodeRabbit

  • Updates
    • Tracker synchronization now uses its updated private destination.
    • Guidance clarifies that the tracker destination is configured separately from the public repository, which is not used for tracker data.
  • Documentation
    • Clarified where tracker synchronization is configured and which repository should not be used for tracker data.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
CLAUDE.md — configured
📝 Walkthrough

Walkthrough

The configured tracker remote now uses the beads-tracker hostname. Sync guidance and the tracker-remote test reflect the updated alias.

Changes

Tracker remote configuration

Layer / File(s) Summary
Update tracker remote alias
.beads/config.yaml, AGENTS.md, CLAUDE.md, tests/test_ci_gates_report_what_they_checked.py
The configured sync.remote URL uses the beads-tracker hostname. Sync guidance refers to the configured private remote. The test assertion checks for the new hostname.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Merge Risk: 🟡 Moderate · up to 31145

Tracker sync may fail or reach a different endpoint unless syncing machines map the new alias to the existing tracker. Confirm that mapping before merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 31145

The change preserves the SSH transport, repository path, and instructions forbidding tracker publication to the public repository. No introduced security defect is established, but the private alias’s destination and authentication settings could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A wrongly resolved or authorized tracker destination could expose synchronized issue data, which the existing tests describe as containing real wallet addresses. The evidence does not show such a misconfiguration or establish additional tenant, service, or environment exposure.

Trust Boundaries and Controls

  • observed — The private-tracker versus public-repository boundary remains explicit in both instruction files. They still forbid adding the public repository as a Dolt remote or pushing refs/dolt/* to it.
  • inferred — The updated hostname assertion is a committed-configuration guard, not runtime destination enforcement. The former assertion also lacked runtime attestation; no authentication bypass or attacker-controlled alias mapping is demonstrated by this PR.

Resilience and Maintainability Implications

  • observed — Existing instructions require stopping and reporting blocked sync or push operations, and retain approval requirements for commits and pushes. These are workflow controls, not proof that the external sync implementation fails closed.

Hardening Proposals

  • proposed — Privately verify that beads-tracker resolves to the intended private host and port with the expected host authentication and credentials before syncing. Keep this operational verification separate from the public hostname assertion and do not publish private connection details.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: replacing the private tracker address with an alias so the repository no longer exposes its location.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (3 skipped: 3 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

coderabbitai[bot]

This comment was marked as outdated.

Comment thread .beads/config.yaml
@GeiserX
GeiserX merged commit e131738 into main Oct 4, 2026
10 checks passed
@GeiserX
GeiserX deleted the chore/beads-tracker-alias branch October 4, 2026 19:17
Repository owner deleted a comment from coderabbitai Bot Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant