Skip to content

Declarative rulesets and repository registry with drift plan - #311

Merged
hdamker merged 4 commits into
camaraproject:mainfrom
hdamker:feat/repository-config-rulesets
Oct 7, 2026
Merged

hdamker merged 4 commits into
camaraproject:mainfrom
hdamker:feat/repository-config-rulesets

Conversation

@hdamker

@hdamker hdamker commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What type of PR is this?

  • enhancement/feature
  • repository management

What this PR does / why we need it:

Declares the repository rulesets once and adds a tool that reports where a repository differs: config/rulesets/*.json (the three release rulesets, release-tag-protection and the two main rulesets), config/ruleset-classes.yaml (which ruleset class carries which rulesets) and config/repositories.yaml (one entry per organisation repository, with its ruleset_class). workflows/repository-config/ provides plan (create, update with diff, remove, unmanaged, classic branch protection) and apply for named repositories, with tests over recorded API responses. A weekly workflow runs plan with a dedicated GitHub App and fails on drift; a second workflow runs the tests. scripts/apply-release-rulesets.sh is removed.

  • One declared copy of each ruleset instead of script heredocs, template UI state and documentation JSON
  • main branch protection brought to one model across repositories
  • Drift visible per repository before anything is changed

The first plan shows release-tag-protection to be created on the API repositories and the main changes; apply stays a manual CLI step per repository.

Which issue(s) this PR fixes:

Part of #310

Special notes for reviewers:

Follow-up PRs: the repository creation workflow applies the declared set instead of copying template rulesets, and tooling's repository-setup.md links to these files.

Related: camaraproject/ReleaseManagement#676

Changelog input

Repository rulesets declared in config/ with a plan/apply tool and weekly drift plan; apply-release-rulesets.sh removed

Additional documentation

workflows/repository-config/README.md

@hdamker
hdamker requested review from a team as code owners October 5, 2026 08:12
@hdamker

hdamker commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

Rollout after merge (CLI apply, whole per-repository plan, ordered by repository):

  1. ReleaseTest, CommonalitiesTest, Template_API_Repository. Then verify on ReleaseTest: codeowner merge works, manual release-tag publish is refused.
  2. ReleaseManagement, project-administration, tooling (first classic-protection removal on ReleaseManagement).
  3. API repositories with an active release.
  4. All other API repositories.
  5. Working group, Sub Project and Provider Implementation repositories.

Merge rights stay as they are: classic protection is removed only after the main rulesets are active, and its one required approval is carried by Codeowner_review_required.

First plan (2026-10-05, local run, 611 API calls): 96 repositories, 11 clean, 85 with drift, 0 errors. Release rulesets on API repositories match the declared files. Changes: release-tag-protection created on 67 API repositories, main rulesets created where missing, 10 disabled Codeowner_review_required activated on repositories with several codeowners, 8 disabled copies removed on single-codeowner repositories, 7 retired rulesets removed, classic protection removed on 40 repositories, release rulesets removed from EdgeCloud (not an API repository), Only_Codeowner_Can_Merge on tooling set to 0 required approvals. Full result attached.

repository-config-plan-2026-10-05.md

@hdamker

hdamker commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Merging to get #312 and the PR in tooling unblocked.

@hdamker
hdamker merged commit 711f47f into camaraproject:main Oct 7, 2026
2 checks passed
@hdamker
hdamker deleted the feat/repository-config-rulesets branch October 7, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant