fix(repos): omit the default private and internal forking setting - #106
Merged
Merged
Conversation
A 422 in run 36578849679 showed the rejected organization-private transition request. Only the omitted-YAML default changes: private and internal repositories now resolve to null, while public repositories remain true. Explicit values still pass through and now carry a documented prerequisite for organization-owned repositories.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
On 2026-09-29 the control plane flipped
aws-monitoring-terraform-frameworkfrom public to private and the applyended with
422 This organization does not allow private repository forkingon the repository PATCH (run36578849679). The declared end state converged anyway, and later detector runs show no drift, so the failure was
transition-only — but every public→private flip in this organization would hit it.
The provider (integrations/github 6.12.1) sends
allow_forkingin the same PATCH as a visibility change, and onlywhen the attribute changed. This module's default moved
true(public) →false(organization-owned private) withthe flip, so the request carried
allow_forking=falsealongsidevisibility=private, and the organization, whichforbids private forking, rejects the field's presence in that request. Executed against the provider's own update
path: with the attribute configured
falsethe second PATCH carries it; with the attribute omitted, neither PATCHdoes.
What changes
When YAML omits
allow_forking, a private or internal repository now defaults tonull: the field is not sent, soon an organization-owned repository the organization's own setting governs. That is the treatment personal-account
private repositories already had, and the same stance #105 took for organization-enforced security settings. Public
still defaults to
true; explicit YAML values still pass through, and explicitfalseon a public repository isstill rejected.
Explicit values are a separate matter, now documented rather than changed: on an organization-owned private or
internal repository an explicit
allow_forkingrequires the organization to allow private forking first, and amanaged
org_settingsdefaults that tofalse, as this organization has it. The checked-in private declarationsomit the key; plan-time handling of explicit values is a follow-up piece.
allow_forkingis optional and computed with no default in the provider, so an existing repository keeps its storedvalue and plans nothing: the three private repositories in the organization all hold
falsein state and areunaffected whether their declaration omits the key or sets
false(a mocked stateful test with the exact providerplans
No changes).Also corrects documentation that contradicted the code:
README.mdsaid the key was rejected and unmanaged whilethe module allows, defaults and sends it;
DESIGN.mdanddocs/reference/security-posture.mddescribed asingle or ownership-dependent default. Tests F2 and F3 now assert the new defaults.
Effect on the consumer
None until
github-terraform-runnerbumps its framework pin. That pin-bump PR's plan must show zero actionablerows; any row is a finding.