Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
# Requires org-level variable RELEASE_APP_CLIENT_ID and secret RELEASE_APP_PRIVATE_KEY
#
# NOTE: Repository rulesets require admin-level access and are applied separately
# via the apply-release-rulesets.sh script.
# with the repository-config tool, see workflows/repository-config/README.md.
#
# DOCUMENTATION:
# See release_automation/docs/repository-setup.md in camaraproject/tooling
Expand Down
68 changes: 68 additions & 0 deletions .github/workflows/repository-config-plan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
# =========================================================================================
# CAMARA Project - Repository Configuration Plan
#
# Compares the declared repository configuration (config/) with the live state of every
# repository in the organisation and fails when they differ. Read-only: nothing is
# changed. Apply a plan from the command line, see workflows/repository-config/README.md.
#
# AUTHENTICATION:
# - GitHub App camara-repository-config, token minted with create-github-app-token.
# Environment repository-config: variable REPO_CONFIG_APP_CLIENT_ID,
# secret REPO_CONFIG_APP_PRIVATE_KEY. The environment only admits the main branch.
#
# DOCUMENTATION:
# https://github.com/camaraproject/project-administration/blob/main/workflows/repository-config/README.md
# =========================================================================================

name: Repository Configuration Plan

on:
schedule:
- cron: '17 5 * * 1'
workflow_dispatch:
inputs:
repos:
description: 'Comma-separated repository names to plan. Empty = all registry entries.'
required: false
type: string
default: ''

permissions:
contents: read

jobs:
plan:
name: Plan
runs-on: ubuntu-latest
environment: repository-config
steps:
- name: Generate App token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ vars.REPO_CONFIG_APP_CLIENT_ID }}
private-key: ${{ secrets.REPO_CONFIG_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}

- name: Checkout
uses: actions/checkout@v7

- name: Setup Python
uses: actions/setup-python@v7
with:
python-version: '3.14'

- name: Install dependencies
run: pip install PyYAML requests

- name: Plan
working-directory: workflows/repository-config
env:
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
REPOS: ${{ inputs.repos }}
run: |
args=()
if [ -n "$REPOS" ]; then
args+=(--repos "$REPOS")
fi
python -m scripts.cli plan "${args[@]}" --markdown "$GITHUB_STEP_SUMMARY"
37 changes: 37 additions & 0 deletions .github/workflows/repository-config-tests.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# =========================================================================================
# CAMARA Project - Repository Configuration Tests
#
# Runs the unit tests of workflows/repository-config and loads the declared configuration
# in config/ so that an inconsistent change fails before it is merged.
# =========================================================================================

name: Repository Configuration Tests

on:
pull_request:
paths:
- 'workflows/repository-config/**'
- 'config/**'
- '.github/workflows/repository-config-tests.yml'

permissions:
contents: read

jobs:
test:
name: Test
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7

- name: Setup Python
uses: actions/setup-python@v7
with:
python-version: '3.14'

- name: Install dependencies
run: pip install PyYAML requests pytest

- name: Run tests
run: python -m pytest workflows/repository-config/tests
18 changes: 14 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,13 +84,20 @@ Automates setup of new API repositories from [Template_API_Repository](https://g
* **Workflow**: `admin-api-repository-creation.yml`
* **Requirements**: Environment `repository-creation` with `GH_REPO_CREATE_TOKEN`

### Repository Configuration

Declares repository rulesets and `main` branch protection once and reports drift per repository.

* **Location**: [workflows/repository-config/](workflows/repository-config/)
* **Declarations**: [config/repositories.yaml](config/repositories.yaml), [config/ruleset-classes.yaml](config/ruleset-classes.yaml), [config/rulesets/](config/rulesets/)
* **Documentation**: [workflows/repository-config/README.md](workflows/repository-config/README.md)
* **Workflows**: `repository-config-plan.yml` (weekly plan), `repository-config-tests.yml`

### Admin Scripts

Scripts for administrative tasks that complement campaigns.

* **Location**: [scripts/](scripts/)
* **Scripts**:
* `apply-release-rulesets.sh` - Applies release automation rulesets to API repositories (companion to the onboarding campaign)

### Legacy Reporting (to be replaced)

Expand All @@ -116,15 +123,18 @@ project-administration/
│ └── release-plan-rollout/ # Release plan file generation
├── config/ # Shared configuration files
│ ├── api-landscape.yaml # API portfolio metadata
│ └── meta-release-mappings.yaml
│ ├── meta-release-mappings.yaml
│ ├── repositories.yaml # Repository registry
│ ├── ruleset-classes.yaml # Rulesets per ruleset class
│ └── rulesets/ # Declared rulesets (JSON)
├── data/ # Release Collector outputs (master data)
│ └── releases-master.yaml # Master release metadata
├── reports/ # Release Collector outputs (JSON reports)
├── scripts/ # Admin scripts
│ └── apply-release-rulesets.sh
└── workflows/
├── api-repository-creation/ # Repository creation system
│ └── docs/README.md
├── repository-config/ # Rulesets and branch protection: plan, apply
└── release-collector/ # Release tracking system
├── docs/ # Documentation
├── schemas/ # YAML schemas
Expand Down
Loading
Loading