HydraIssues

Rotate the HydraCluster admin token: it was committed in a runbook
open bug Project: hydracluster Reporter: 1 Sep 2026 07:03

Description

The HydraCluster admin token was pasted into docs/runbooks/body-recovery.md in two example commands, so anyone able to read the repository had a working admin credential.

Removed from the file on 2026-09-01 (hydracluster main, commit 0c18119) and replaced with ${HYDRACLUSTER_ADMIN_TOKEN}.

That does not undo the exposure. The value is still in the history of two commits, so it must be treated as compromised:

  • 447da4a Document DELETE /api/v1/nodes/{id}/stream in runbooks
  • 47823a5 Add body-recovery triage runbook + auth-middleware deadlock warning

The token starts c21ff820 and ends 7623b76d. The full value is in those commits and is deliberately not repeated here.

What needs doing:

  • Rotate server.admin_token in the HydraCluster config and restart the service
  • Update anything holding the old value: ~/.hydracluster/config.yaml on operator machines, and any CI secret or service config that authenticates to the cluster API
  • Decide whether to rewrite the two commits. Probably not worth it once the token is rotated, since a rotated token in history is harmless

Found while adding 32-bit ARM enrolment support. Unrelated to that change.