PK · Passphrase + Portal Key
A Portal holds the shared passphrase and hands it to the runner for one build.
One shared passphrase, held by the Portal rather than by GitHub. The runner fetches it for a single build and deletes it before compiling.
The same delivery mechanism as RK, with the simpler encryption mode.
1 · Create the token
Do this first. sgit init uploads the secrets your workflow reads, and without
a token it sets up everything except the half that makes builds run.
GitHub → Settings → Developer settings → Fine-grained tokens → Generate new
| Repository access | Only select repositories → this one |
| Contents | Read and write — so you can push |
| Secrets | Read and write — so init can upload them |
Metadata: read is added for you.
export GITHUB_PAT=github_pat_…GH_TOKEN and GITHUB_TOKEN work too. If none is set and you are at a
terminal, init offers to take it and stores it per project.
2 · Seal the repository
Passphrase mode does not invent your secret — you pick it:
export SGIT_KEY="$(openssl rand -base64 32)"sgit pkpk is the shorthand for this pair, and takes every flag init takes.
Spelled out, it is:
sgit init --mode passphrase --ci-mode portal-keyOn your disk:
passphrase # a copy of $SGIT_KEY, so it outlives the shellEvery key is outside the repository, at 0600. A key in the working tree is
one git add -A from being published.
3 · Check GitHub is ready
sgit init uploaded CODESEAL_BOOTSTRAP_SECRET and GITHUB_WRAPPER_PRIVATE_KEY as it went — that is what the token in step 1
was for. Confirm it landed:
sgit ci verifymylife-inc/demo is ready to build.
The passphrase itself is never a GitHub secret.
4 · Protect something
sgit add-sensitive src/private
sgit encrypt5 · The everyday loop
sgit add -s src/private/payment.rs
sgit commit -- -m "protect payments"
sgit push origin mainPush, and GitHub starts the workflow. The runner exchanges its bootstrap secret for a short-lived token, redeems that for the wrapped passphrase, and unwraps it locally.
What you end up with
| On GitHub | ciphertext, and two secrets that are useless apart |
| In the Portal | the passphrase, stored encrypted |
| Adding a teammate | tell them the passphrase |
| Removing one | rotate everything, and re-provision the Portal |
| To start a build | nothing — GitHub does it |
