Skip to content

ops: manual LongPort token refresh job (dry-run default) - #586

Merged
Pigbibi merged 1 commit into
mainfrom
ops/longport-token-refresh-job-dry-run
Oct 9, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
ops/longport-token-refresh-job-dry-run

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Manual Refresh LongPort Access Token workflow (dry_run=true by default).
  • Live mode (--no-dry-run) calls Legacy /v1/token/refresh with required expired_at, fail-closes on errors, adds one SM token version; never logs secret values.
  • Target order in UI: paper → sg → hk; stderr warning on live hk. No schedule.
  • Runbook A2 updated to point at this workflow.

Depends on correct refresh semantics (QPK #653 for in-runtime bootstrap); this Actions job carries its own expired_at client so it can dry-run / live-refresh without waiting for a pin bump.

Test plan

  • pytest -q tests/test_refresh_longport_access_token.py tests/test_inspect_longport_token_expiry.py (10 passed)
  • After merge: dispatch dry-run for paper, then sg (confirm plan JSON only)
  • Do not run live hk until paper/sg live succeed and VersionAdder IAM is confirmed
  • Confirm deploy SA can secretmanager.versions.add on paper/sg before first live run

Add workflow_dispatch refresh for paper/sg/hk with dry_run=true by
default. Live mode sends expired_at, fail-closes on API errors, and
writes only a new token SM version (names/days in logs). Prefer paper
then sg; warn on live hk. No schedule.
@Pigbibi
Pigbibi merged commit 799b41b into main Oct 9, 2026
1 check passed
@Pigbibi
Pigbibi deleted the ops/longport-token-refresh-job-dry-run branch October 9, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant