diff --git a/modules/common_repository/README.md b/modules/common_repository/README.md index 6b66bd5..ee86232 100644 --- a/modules/common_repository/README.md +++ b/modules/common_repository/README.md @@ -57,6 +57,7 @@ module "repo_docs" { |------|-------------|------|---------|:--------:| | [all\_members\_permission](#input\_all\_members\_permission) | Permission for all organization members | `string` | `"triage"` | no | | [branch\_protection](#input\_branch\_protection) | Configure branch protection if true | `bool` | `true` | no | +| [custom\_repository\_roles](#input\_custom\_repository\_roles) | Names of custom repository roles accepted for team and user access | `list(string)` | `[]` | no | | [description](#input\_description) | Repository description | `string` | `""` | no | | [is\_template](#input\_is\_template) | Set this to true if this is a template repository | `bool` | `false` | no | | [labels](#input\_labels) | List of labels to configure on the repository |
list(object({
name = string
color = string
description = string
})) | `null` | no |
diff --git a/modules/common_repository/README.md.in b/modules/common_repository/README.md.in
index 993aafd..66d8ae8 100644
--- a/modules/common_repository/README.md.in
+++ b/modules/common_repository/README.md.in
@@ -29,3 +29,25 @@ module "repo_docs" {
]
}
```
+
+### A repository collaborator with a custom repository role
+
+Create the organization-level custom role separately, then list its name in
+`custom_repository_roles` so the module accepts it for repository teams or
+users. GitHub custom repository roles require Enterprise Cloud.
+
+```
+module "repo_osac" {
+ source = "./modules/common_repository"
+ name = "osac"
+ description = "OSAC mono-repo"
+
+ custom_repository_roles = [github_organization_repository_role.environment_manager.name]
+ teams = [
+ {
+ team_id = "infrastructure"
+ permission = github_organization_repository_role.environment_manager.name
+ }
+ ]
+}
+```
diff --git a/modules/common_repository/variables.tf b/modules/common_repository/variables.tf
index 689026b..a75ac11 100644
--- a/modules/common_repository/variables.tf
+++ b/modules/common_repository/variables.tf
@@ -69,13 +69,19 @@ variable "teams" {
}))
default = []
validation {
- error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin"
+ error_message = "permission must be a standard repository role or a name in custom_repository_roles"
condition = alltrue([
- for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission)
+ for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission)
])
}
}
+variable "custom_repository_roles" {
+ description = "Names of custom repository roles accepted for team and user access"
+ type = list(string)
+ default = []
+}
+
variable "users" {
description = "Users with access to this repository"
type = list(object({
@@ -84,9 +90,9 @@ variable "users" {
}))
default = []
validation {
- error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin"
+ error_message = "permission must be a standard repository role or a name in custom_repository_roles"
condition = alltrue([
- for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission)
+ for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission)
])
}
}
diff --git a/organization.tf b/organization.tf
index 473e62c..7a2016b 100644
--- a/organization.tf
+++ b/organization.tf
@@ -23,6 +23,20 @@ resource "github_organization_role" "runner_manager" {
]
}
+# Let the infrastructure team manage Actions environments in the osac
+# repository while retaining write access to its code. GitHub's
+# manage-environments permission also includes environment secrets and
+# variables.
+resource "github_organization_repository_role" "osac_environment_manager" {
+ name = "osac-environment-manager"
+ description = "Write access plus GitHub Actions environment management for osac"
+ base_role = "write"
+
+ permissions = [
+ "manage_environments",
+ ]
+}
+
resource "github_organization_role_team" "runner_manager_wg_infra" {
role_id = github_organization_role.runner_manager.role_id
team_slug = github_team.all["wg-infra"].slug
diff --git a/repositories.tf b/repositories.tf
index 93daca6..55c9dd9 100644
--- a/repositories.tf
+++ b/repositories.tf
@@ -149,7 +149,7 @@ module "repo_osac" {
},
{
team_id = "infrastructure"
- permission = "push"
+ permission = github_organization_repository_role.osac_environment_manager.name
},
{
team_id = "wg-osac-storage"
@@ -199,10 +199,12 @@ module "repo_osac" {
github_team.all["infrastructure"].id,
]
+ custom_repository_roles = [github_organization_repository_role.osac_environment_manager.name]
+
environments = [{
name = "copr-production"
reviewers = {
- teams = [github_team.all["wg-infra"].id]
+ teams = [github_team.all["infrastructure"].id]
}
}]