Let repoAccess.ts entries create and own repositories - #200
Merged
Merged
Conversation
A repository entry in src/config/repoAccess.ts can now be one of two kinds: - Access-only (unchanged): the repository pre-dates this config and Pulumi manages only its collaborators. Every existing entry stays this kind. - Managed: the entry carries a `settings` block (description, optional visibility/homepage/topics/template). Pulumi creates the repository from REPOSITORY_DEFAULTS plus those settings, then manages its collaborators, so a new repository and its access land in one deploy. Working group leads can create a repository by opening a PR that adds one entry. Removing a managed entry archives the repository rather than deleting it (archiveOnDestroy). Validation rejects duplicate repository names and, for managed entries, invalid names, empty descriptions, missing admin grants and templates that are not declared org repositories. This commit declares no managed repository, so it produces no resource changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Kuh5eR5uDFfknR1vRPEkfn
Pulumi PreviewClick to expand preview output |
The deploy runs `pulumi up --refresh`, so a managed repository archived by hand in GitHub would be refreshed to archived=true and then planned back to false, un-archiving it. Ignore `archived` on the Repository resource so the manual state sticks; archiving via this config (removing the entry, which archiveOnDestroy turns into an archive) is unaffected. Also document that adding `settings` to an existing repository does not adopt it (import first), and that the `repository` key is the Pulumi resource name, so renaming it in place archives the old repository. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Kuh5eR5uDFfknR1vRPEkfn
localden
approved these changes
Sep 30, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Den Delimarsky · Slack thread
Before: creating a repository in the org means an org owner clicking through GitHub (
membersCanCreateRepositoriesis off inorgSettings.ts), and then a second PR here to declare its access inrepoAccess.ts. Working group leads cannot do either step themselves.After: a repository entry in
src/config/repoAccess.tsmay carry asettingsblock (description, optionalvisibility,homepage,topics,template). The deploy then creates the repository and its collaborators in one apply, so a WG lead creates a repository by opening a PR that adds one entry, and core-maintainers review it via CODEOWNERS. Existing entries are unchanged (access-only; no import). This PR itself declares no managed repository, sopulumi previewshould show no resource changes.Removing a managed entry archives the repository instead of deleting it (
archiveOnDestroy: true, guarded by a test), andnpm run validaterejects duplicate repository names and, for managed entries, names outside^[a-z0-9][a-z0-9._-]*$, empty descriptions, entries with noadminteam or user, and templates that are not themselves declared inrepoAccess.ts.How: for each entry with
settings,src/github.tscreates agithub.Repositorykeyedrepository-<name>fromREPOSITORY_DEFAULTSplus the entry's settings, and passes itsnameoutput as therepositoryof the existingrepo-<name>RepositoryCollaboratorsresource (resource names unchanged, so state is continuous), which gives the create-then-grant ordering.REPOSITORY_DEFAULTS(squash-only merges, delete branch on merge,PR_TITLE/PR_BODYsquash messages, no wiki/projects/discussions, Apache-2.0 license, auto-init, vulnerability alerts, archive on destroy) mirrors the org's extension repositories: license, wiki, projects and discussions flags were read from the liveext-tasks,ext-skillsandexperimental-ext-interceptorsrepositories (majority values); the merge-strategy fields are not exposed by that listing and follow the SDK repos' conventional setup, so please adjust if the org prefers otherwise. Template owner reusesGITHUB_ORGfromaccessPolicies.ts. README gains a "Creating a new repository (working group leads)" section.Before first use
PULUMI_GITHUB_TOKEN(deploy and preview workflows) is an org-owner token with thereposcope, whichPOST /orgs/{org}/reposrequires; it already has org-admin rights for the existing resources.ext-template) and declare it inrepoAccess.tsso new extension repos can setsettings.template.REPOSITORY_DEFAULTSagainst the org's preferred merge settings before the first managed entry lands.🤖 Generated with Claude Code
https://claude.ai/code/session_01Kuh5eR5uDFfknR1vRPEkfn
Generated by Claude Code