Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions modules/common_repository/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ module "repo_docs" {
|------|-------------|------|---------|:--------:|
| <a name="input_all_members_permission"></a> [all\_members\_permission](#input\_all\_members\_permission) | Permission for all organization members | `string` | `"triage"` | no |
| <a name="input_branch_protection"></a> [branch\_protection](#input\_branch\_protection) | Configure branch protection if true | `bool` | `true` | no |
| <a name="input_custom_repository_roles"></a> [custom\_repository\_roles](#input\_custom\_repository\_roles) | Names of custom repository roles accepted for team and user access | `list(string)` | `[]` | no |
| <a name="input_description"></a> [description](#input\_description) | Repository description | `string` | `""` | no |
| <a name="input_is_template"></a> [is\_template](#input\_is\_template) | Set this to true if this is a template repository | `bool` | `false` | no |
| <a name="input_labels"></a> [labels](#input\_labels) | List of labels to configure on the repository | <pre>list(object({<br/> name = string<br/> color = string<br/> description = string<br/> }))</pre> | `null` | no |
Expand Down
22 changes: 22 additions & 0 deletions modules/common_repository/README.md.in
Original file line number Diff line number Diff line change
Expand Up @@ -29,3 +29,25 @@ module "repo_docs" {
]
}
```

### A repository collaborator with a custom repository role

Create the organization-level custom role separately, then list its name in
`custom_repository_roles` so the module accepts it for repository teams or
users. GitHub custom repository roles require Enterprise Cloud.

```
module "repo_osac" {
source = "./modules/common_repository"
name = "osac"
description = "OSAC mono-repo"

custom_repository_roles = [github_organization_repository_role.environment_manager.name]
teams = [
{
team_id = "infrastructure"
permission = github_organization_repository_role.environment_manager.name
}
]
}
```
14 changes: 10 additions & 4 deletions modules/common_repository/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -69,13 +69,19 @@ variable "teams" {
}))
default = []
validation {
error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin"
error_message = "permission must be a standard repository role or a name in custom_repository_roles"
condition = alltrue([
for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission)
for v in var.teams : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission)
])
}
}

variable "custom_repository_roles" {
description = "Names of custom repository roles accepted for team and user access"
type = list(string)
default = []
}

variable "users" {
description = "Users with access to this repository"
type = list(object({
Expand All @@ -84,9 +90,9 @@ variable "users" {
}))
default = []
validation {
error_message = "unknown permission: permission must be one of pull, push, maintain, triage, or admin"
error_message = "permission must be a standard repository role or a name in custom_repository_roles"
condition = alltrue([
for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission)
for v in var.users : contains(["pull", "push", "maintain", "triage", "admin"], v.permission) || contains(var.custom_repository_roles, v.permission)
])
}
}
Expand Down
14 changes: 14 additions & 0 deletions organization.tf
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,20 @@ resource "github_organization_role" "runner_manager" {
]
}

# Let the infrastructure team manage Actions environments in the osac
# repository while retaining write access to its code. GitHub's
# manage-environments permission also includes environment secrets and
# variables.
resource "github_organization_repository_role" "osac_environment_manager" {
name = "osac-environment-manager"
description = "Write access plus GitHub Actions environment management for osac"
base_role = "write"

permissions = [
"manage_environments",
]
}

resource "github_organization_role_team" "runner_manager_wg_infra" {
role_id = github_organization_role.runner_manager.role_id
team_slug = github_team.all["wg-infra"].slug
Expand Down
6 changes: 4 additions & 2 deletions repositories.tf
Original file line number Diff line number Diff line change
Expand Up @@ -149,7 +149,7 @@ module "repo_osac" {
},
{
team_id = "infrastructure"
permission = "push"
permission = github_organization_repository_role.osac_environment_manager.name
},
{
team_id = "wg-osac-storage"
Expand Down Expand Up @@ -199,10 +199,12 @@ module "repo_osac" {
github_team.all["infrastructure"].id,
]

custom_repository_roles = [github_organization_repository_role.osac_environment_manager.name]

environments = [{
name = "copr-production"
reviewers = {
teams = [github_team.all["wg-infra"].id]
teams = [github_team.all["infrastructure"].id]
}
}]

Expand Down
Loading