Add repospawner machine user scoped to terraform-git
repospawner opens repo-creation PRs against terraform-git and needs no other access, so give it its own identity and a per-repo team instead of adding it to the org-wide agents team. - add config/git.unkin.net/user/repospawner.yaml (limited visibility, not admin, no org/repo creation), mirroring the unkin-agent bot posture - add config/git.unkin.net/unkin/team/repospawner.yaml granting write on the terraform-git repository only (include_all_repositories false)
This commit is contained in:
@@ -0,0 +1,16 @@
|
|||||||
|
# Least-privilege access for the repospawner bot: Write on terraform-git only,
|
||||||
|
# which is the minimum Gitea permission that allows pushing a branch and opening
|
||||||
|
# a pull request. repospawner does its whole job here (repo-creation PRs), so it
|
||||||
|
# is kept out of the org-wide "agents" team (include_all_repositories: true).
|
||||||
|
#
|
||||||
|
# Merge stays reserved for Ben: branch protection on terraform-git's main sets a
|
||||||
|
# merge whitelist of the Owners team only. Keep this team out of every merge and
|
||||||
|
# approval whitelist.
|
||||||
|
description: "repospawner bot -- push branches + open PRs on terraform-git only"
|
||||||
|
permission: write
|
||||||
|
include_all_repositories: false
|
||||||
|
can_create_repos: false
|
||||||
|
repositories:
|
||||||
|
- terraform-git
|
||||||
|
members:
|
||||||
|
- repospawner
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
# Service identity for repospawner, which opens pull requests against this
|
||||||
|
# repository (terraform-git) to add new Gitea repositories on request. It is
|
||||||
|
# deliberately separate from unkin-agent so its access can stay scoped to the
|
||||||
|
# single repository it needs: the "repospawner" team (unkin/team/repospawner.yaml)
|
||||||
|
# grants Write on terraform-git and nothing else.
|
||||||
|
#
|
||||||
|
# Auth is via ephemeral API tokens minted by the vault-plugin-secrets-gitea
|
||||||
|
# engine -- no usable credential lives in this repo's state beyond the generated
|
||||||
|
# placeholder. Merge stays blocked by branch protection (merge whitelist =
|
||||||
|
# Owners only), so it can push branches and open PRs but never merge.
|
||||||
|
email: repospawner@unkin.net
|
||||||
|
full_name: "Repo Spawner"
|
||||||
|
description: "repospawner service identity -- opens repo-creation PRs against terraform-git"
|
||||||
|
# Conservative bot posture: not a site admin, cannot create orgs or repos,
|
||||||
|
# profile visible only to signed-in users.
|
||||||
|
visibility: limited
|
||||||
|
admin: false
|
||||||
|
allow_create_organization: false
|
||||||
|
max_repo_creation: 0
|
||||||
Reference in New Issue
Block a user