| domain | operations |
|---|---|
| type | concept |
| owner | <!-- team/role that owns repository configuration --> |
| last_reviewed |
How this repository's GitHub settings are configured and secured, as actually managed under terraform/ today.
Using the integrations/github provider, applied manually (not from CI, see terraform/README.md). The resources live in a reusable module, terraform/github-repository/, instantiated by the root config (terraform/main.tf) for this repository specifically:
| Resource | Manages |
|---|---|
module.github_repository.github_repository.this |
Merge methods (squash + rebase only, no merge commits), auto-merge disabled, delete-branch-on-merge, secret scanning + push protection |
module.github_repository.github_repository_ruleset.main |
Ruleset (not classic branch protection) targeting ~DEFAULT_BRANCH: require a pull request and passing CI (lint, test, build) before merging; block force-pushes/deletion except for the admin repository role |
module.github_repository.github_repository_environment.production, ...staging |
The two fixed deployment environments every repo this module manages gets |
github_repository_collaborators (commented out) |
Opt-in: the full, authoritative collaborator list, for adding maintainers beyond the repo owner |
The default branch requires a pull request, passing CI, and one approving review (required_approving_review_count, default 1; solo maintainers should override it to 0 in terraform.tfvars, since GitHub won't let you approve your own PR). The admin repository role can always bypass the ruleset so an emergency merge/force-push stays possible.
- Visibility, the "template repository" flag, description, topics,
has_issues/has_wiki/..., deliberately left alone (ignore_changesingithub-repository/main.tf), since they're not part of "secure the repository" and touching them risks unrelated drift. - CodeQL / code scanning default setup: no Terraform resource exists for this in the provider. Enabled once, manually, via Settings → Code security → Code scanning → "Set up" → Default.
- terraform/README.md: prerequisites, how to run, one-time import steps
- CI/CD pipeline, the
lint/test/buildchecks required by the ruleset