fix: grant admins team repo access so protection bypass actors converge - #20
Merged
Conversation
Contributor
OpenTofu Plan |
xnoto
added a commit
that referenced
this pull request
Aug 30, 2026
## Summary Excludes every repository in `local.private_github_repositories` from both standard and relaxed `github_branch_protection` resources. This makes the policy explicit and future-proof: private personal repositories are outside the organization review policy, and GitHub Free cannot apply the configured branch restrictions to them. `agent-knowledge` remains private and receives no Terraform-managed branch protection. ## Why now The just-merged auto-merge setting change partially applied: `kustomize-cluster.allow_auto_merge` completed, then the apply failed trying to create relaxed protection for private `agent-knowledge` with: > Upgrade to GitHub Pro or make this repository public to enable this feature. This PR removes the unsupported resource from the desired state, allowing the next environment-gated apply to converge successfully. ## Expected plan - No `agent-knowledge` branch-protection creation. - `kustomize-cluster.allow_auto_merge` should already be converged from the partial apply; CI plan is authoritative for confirming that. - No secrets, repository visibility, branch protections on public repositories, or GitHub App permissions change. ## Follow-up Once this root apply succeeds, charts PR #20 can merge. The next real `opencode-server` release will then prove that GitHub auto-merges the generated version-pin PR after `kustomize-cluster` `test` passes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GitHub silently drops branch-protection bypass actors that have no repository access at write time — the apply succeeds but the stored rule omits them, so every plan re-added
makeitworkcloud/adminstodismissal_restrictions/pull_request_bypassers/push_allowanceson all 11 repos (perpetual diff).gh-iam.tf:github_team_repository.adminsgrants the teamadminon every active repository (xnoto is the only member and already owner — no effective permission change). Team description updated for the dual role.gh-protections.tf:depends_onincludes the grants so they land before protections are written — converges in a single apply instead of self-healing a cycle later.AGENTS.md: Branch Protection note updated from under-investigation to the root cause and the grants/bypass linkage rule.This plan will show the phantom protection diff one last time (computed before the grants exist); the next plan after this apply should show zero protection changes.