Skip to content

Add tag ruleset support, restrict osac-release/* creation to osac-ci - #246

Merged
eliorerz merged 1 commit into
mainfrom
add-osac-release-tag-ruleset
Oct 5, 2026
Merged

eliorerz merged 1 commit into
mainfrom
add-osac-release-tag-ruleset

Conversation

@eliorerz

@eliorerz eliorerz commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • New reusable tag_rulesets input on modules/common_repository: for each entry, creates a ruleset allowing tag creation only to the listed GitHub App IDs, plus a separate ruleset blocking tag updates/deletions for everyone unconditionally (no bypass, not even the creating app).
  • Wires this up for osac: only the osac-ci app may create osac-release/* tags (the release marker tag that triggers a Konflux staging release, see NO-ISSUE: Trigger Konflux builds for all 8 components on real releases osac#1424), and nobody may move or delete one once pushed.

Why

Right now the repo has zero tag protection -- anyone with push access could push a fake osac-release/* tag with an arbitrary commit and trigger a Konflux staging release for it. This closes that gap.

Test plan

  • tofu fmt -check, tofu init, tofu validate all pass (OpenTofu 1.9.1)
  • After merge, confirm apply.yaml succeeds and the two new rulesets appear on osac-project/osac

Summary

  • Repository configuration: Added the reusable tag_rulesets input to modules/common_repository. Each entry creates active tag-creation and tag-immutability rulesets. Archived repositories do not receive these rulesets.
  • osac repository: Configured osac-release/* tags so only the osac-ci GitHub App (ID 4966101) can create them. The ruleset blocks updates and deletions without bypasses.
  • API and compatibility: The module input is additive and defaults to an empty list. Existing module callers need no changes. Configurations that set tag_rulesets now manage additional GitHub rulesets.
  • Other areas: No controller, database, authentication, deployment, CI, test, or documentation changes are identified in the supplied change summary. No test files are listed.
  • Validation: The PR objectives report that tofu fmt -check, tofu init, and tofu validate passed with OpenTofu 1.9.1. Applying the change and confirming the rulesets on GitHub remain untested.

Risk classification

Risk label and labeling criteria are not provided in the available evidence, so the applied label and any comparison with a nearby classification cannot be determined.

New reusable tag_rulesets input on modules/common_repository: for each
entry, creates a ruleset allowing tag creation only to the listed
GitHub App IDs, plus a separate ruleset blocking tag updates/deletions
for everyone unconditionally (no bypass, not even the creating app).

Wires this up for osac specifically: only the osac-ci app may create
osac-release/* tags (the release marker tag that triggers a Konflux
staging release, see osac-project/osac#1424), and nobody may move or
delete one once pushed.

Validated with tofu fmt/init/validate (OpenTofu 1.9.1); this repo's
pre-commit only checks fmt, actual apply happens automatically on
merge to main via apply.yaml.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 0c7a1a33-6141-4123-a86b-57a8b6672f76
📥 Commits

Reviewing files that changed from the base of the PR and between e416820 and f36845e.

📒 Files selected for processing (3)
  • modules/common_repository/main.tf
  • modules/common_repository/variables.tf
  • repositories.tf

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review.


Walkthrough

The common repository module now supports paired tag creation and immutability rulesets. The OSAC repository configures these rules for release tags, with creation bypass limited to the osac-ci app.

Changes

Tag Ruleset Configuration

Layer / File(s) Summary
Define and create tag rulesets
modules/common_repository/variables.tf, modules/common_repository/main.tf
Adds the tag_rulesets input and creates active tag creation and immutability rulesets for non-archived repositories.
Configure OSAC release tags
repositories.tf
Adds rules for refs/tags/osac-release/*. The osac-ci app can bypass the creation rule; no bypass actors are configured for the immutability rule.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested labels: risk:ask

Suggested reviewers: larsks

Merge Risk: ⚪ Minimal · up to f3684

This change adds tag protection for OSAC release tags, allowing only the osac-ci app to create them and blocking updates and deletions. No merge-blocking risk is evident. The rulesets are applied automatically on merge, so confirm they appear on the repository afterward.

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the reusable tag ruleset support and the restriction on creating osac-release/* tags.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed The diff adds only ruleset configuration, ref patterns, and the numeric GitHub App integration ID 4966101 labeled osac-ci. It contains no hardcoded credentials, credential-bearing URLs, private-ke…
No-Weak-Crypto ✅ Passed The PR adds Terraform variables and GitHub tag ruleset resources. The changed code contains no MD5, SHA-1, DES-family, RC4, Blowfish, ECB, custom cryptography, or secret/token comparison usage.
No-Injection-Vectors ✅ Passed The pull request adds Terraform ruleset resources and input configuration. The changed code contains no SQL concatenation, shell execution, eval/exec, pickle or YAML loading, os.system calls, or dange…
Container-Privileges ✅ Passed The pull request changes only Terraform repository ruleset configuration and inputs. It adds GitHub tag-creation and tag-immutability rulesets. It does not change container or Kubernetes manifests, or…
No-Sensitive-Data-In-Logs ✅ Passed The PR adds GitHub tag-ruleset configuration and a tag_rulesets input. The changed lines contain no logging statements or sensitive data; the configured pattern and GitHub App ID do not match the list…
Ai-Attribution ✅ Passed The PR description and commit message do not mention use of AI tools. The commit has no Assisted-by, Generated-by, or AI-related Co-Authored-By trailer, so the attribution condition is not trigg…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot added the risk:ask label Oct 5, 2026
@eliorerz
eliorerz merged commit 246a874 into main Oct 5, 2026
2 of 3 checks passed
@eliorerz
eliorerz deleted the add-osac-release-tag-ruleset branch October 5, 2026 20:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant