Repository navigation
Add tag ruleset support, restrict osac-release/* creation to osac-ci - #246
Conversation
New reusable tag_rulesets input on modules/common_repository: for each entry, creates a ruleset allowing tag creation only to the listed GitHub App IDs, plus a separate ruleset blocking tag updates/deletions for everyone unconditionally (no bypass, not even the creating app). Wires this up for osac specifically: only the osac-ci app may create osac-release/* tags (the release marker tag that triggers a Konflux staging release, see osac-project/osac#1424), and nobody may move or delete one once pushed. Validated with tofu fmt/init/validate (OpenTofu 1.9.1); this repo's pre-commit only checks fmt, actual apply happens automatically on merge to main via apply.yaml.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review. WalkthroughThe common repository module now supports paired tag creation and immutability rulesets. The OSAC repository configures these rules for release tags, with creation bypass limited to the ChangesTag Ruleset Configuration
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested labels: Suggested reviewers: Merge Risk: ⚪ Minimal · up to This change adds tag protection for OSAC release tags, allowing only the osac-ci app to create them and blocking updates and deletions. No merge-blocking risk is evident. The rulesets are applied automatically on merge, so confirm they appear on the repository afterward. 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
tag_rulesetsinput onmodules/common_repository: for each entry, creates a ruleset allowing tag creation only to the listed GitHub App IDs, plus a separate ruleset blocking tag updates/deletions for everyone unconditionally (no bypass, not even the creating app).osac: only theosac-ciapp may createosac-release/*tags (the release marker tag that triggers a Konflux staging release, see NO-ISSUE: Trigger Konflux builds for all 8 components on real releases osac#1424), and nobody may move or delete one once pushed.Why
Right now the repo has zero tag protection -- anyone with push access could push a fake
osac-release/*tag with an arbitrary commit and trigger a Konflux staging release for it. This closes that gap.Test plan
tofu fmt -check,tofu init,tofu validateall pass (OpenTofu 1.9.1)apply.yamlsucceeds and the two new rulesets appear onosac-project/osacSummary
tag_rulesetsinput tomodules/common_repository. Each entry creates active tag-creation and tag-immutability rulesets. Archived repositories do not receive these rulesets.osacrepository: Configuredosac-release/*tags so only theosac-ciGitHub App (ID4966101) can create them. The ruleset blocks updates and deletions without bypasses.tag_rulesetsnow manage additional GitHub rulesets.tofu fmt -check,tofu init, andtofu validatepassed with OpenTofu 1.9.1. Applying the change and confirming the rulesets on GitHub remain untested.Risk classification
Risk label and labeling criteria are not provided in the available evidence, so the applied label and any comparison with a nearby classification cannot be determined.