diff --git a/modules/common_repository/README.md b/modules/common_repository/README.md index 6b66bd5..ee86232 100644 --- a/modules/common_repository/README.md +++ b/modules/common_repository/README.md @@ -57,6 +57,7 @@ module "repo_docs" { |------|-------------|------|---------|:--------:| | [all\_members\_permission](#input\_all\_members\_permission) | Permission for all organization members | `string` | `"triage"` | no | | [branch\_protection](#input\_branch\_protection) | Configure branch protection if true | `bool` | `true` | no | +| [custom\_repository\_roles](#input\_custom\_repository\_roles) | Names of custom repository roles accepted for team and user access | `list(string)` | `[]` | no | | [description](#input\_description) | Repository description | `string` | `""` | no | | [is\_template](#input\_is\_template) | Set this to true if this is a template repository | `bool` | `false` | no | | [labels](#input\_labels) | List of labels to configure on the repository |
list(object({
name = string
color = string
description = string
}))
| `null` | no | diff --git a/modules/common_repository/README.md.in b/modules/common_repository/README.md.in index 993aafd..66d8ae8 100644 --- a/modules/common_repository/README.md.in +++ b/modules/common_repository/README.md.in @@ -29,3 +29,25 @@ module "repo_docs" { ] } ``` + +### A repository collaborator with a custom repository role + +Create the organization-level custom role separately, then list its name in +`custom_repository_roles` so the module accepts it for repository teams or +users. GitHub custom repository roles require Enterprise Cloud. + +``` +module "repo_osac" { + source = "./modules/common_repository" + name = "osac" + description = "OSAC mono-repo" + + custom_repository_roles = [github_organization_repository_role.environment_manager.name] + teams = [ + { + team_id = "infrastructure" + permission = github_organization_repository_role.environment_manager.name + } + ] +} +``` diff --git a/modules/common_repository/variables.tf b/modules/common_repository/variables.tf index 689026b..a75ac11 100644 --- a/modules/common_repository/variables.tf +++ b/modules/common_repository/variables.tf @@ -69,13 +69,19 @@ variable "teams" { })) default = [] validation { - error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin" + error_message = "permission must be a standard repository role or a name in custom_repository_roles" condition = alltrue([ - for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) + for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission) ]) } } +variable "custom_repository_roles" { + description = "Names of custom repository roles accepted for team and user access" + type = list(string) + default = [] +} + variable "users" { description = "Users with access to this repository" type = list(object({ @@ -84,9 +90,9 @@ variable "users" { })) default = [] validation { - error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin" + error_message = "permission must be a standard repository role or a name in custom_repository_roles" condition = alltrue([ - for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) + for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission) ]) } } diff --git a/organization.tf b/organization.tf index 473e62c..7a2016b 100644 --- a/organization.tf +++ b/organization.tf @@ -23,6 +23,20 @@ resource "github_organization_role" "runner_manager" { ] } +# Let the infrastructure team manage Actions environments in the osac +# repository while retaining write access to its code. GitHub's +# manage-environments permission also includes environment secrets and +# variables. +resource "github_organization_repository_role" "osac_environment_manager" { + name = "osac-environment-manager" + description = "Write access plus GitHub Actions environment management for osac" + base_role = "write" + + permissions = [ + "manage_environments", + ] +} + resource "github_organization_role_team" "runner_manager_wg_infra" { role_id = github_organization_role.runner_manager.role_id team_slug = github_team.all["wg-infra"].slug diff --git a/repositories.tf b/repositories.tf index 93daca6..55c9dd9 100644 --- a/repositories.tf +++ b/repositories.tf @@ -149,7 +149,7 @@ module "repo_osac" { }, { team_id = "infrastructure" - permission = "push" + permission = github_organization_repository_role.osac_environment_manager.name }, { team_id = "wg-osac-storage" @@ -199,10 +199,12 @@ module "repo_osac" { github_team.all["infrastructure"].id, ] + custom_repository_roles = [github_organization_repository_role.osac_environment_manager.name] + environments = [{ name = "copr-production" reviewers = { - teams = [github_team.all["wg-infra"].id] + teams = [github_team.all["infrastructure"].id] } }]