4b30ba0cfd
repospawner opens repo-creation PRs against terraform-git and needs no other access, so give it its own identity and a per-repo team instead of adding it to the org-wide agents team. - add config/git.unkin.net/user/repospawner.yaml (limited visibility, not admin, no org/repo creation), mirroring the unkin-agent bot posture - add config/git.unkin.net/unkin/team/repospawner.yaml granting write on the terraform-git repository only (include_all_repositories false)
20 lines
1020 B
YAML
20 lines
1020 B
YAML
# Service identity for repospawner, which opens pull requests against this
|
|
# repository (terraform-git) to add new Gitea repositories on request. It is
|
|
# deliberately separate from unkin-agent so its access can stay scoped to the
|
|
# single repository it needs: the "repospawner" team (unkin/team/repospawner.yaml)
|
|
# grants Write on terraform-git and nothing else.
|
|
#
|
|
# Auth is via ephemeral API tokens minted by the vault-plugin-secrets-gitea
|
|
# engine -- no usable credential lives in this repo's state beyond the generated
|
|
# placeholder. Merge stays blocked by branch protection (merge whitelist =
|
|
# Owners only), so it can push branches and open PRs but never merge.
|
|
email: repospawner@unkin.net
|
|
full_name: "Repo Spawner"
|
|
description: "repospawner service identity -- opens repo-creation PRs against terraform-git"
|
|
# Conservative bot posture: not a site admin, cannot create orgs or repos,
|
|
# profile visible only to signed-in users.
|
|
visibility: limited
|
|
admin: false
|
|
allow_create_organization: false
|
|
max_repo_creation: 0
|