Skip to content

Add internal infrastructure team (SRE) - #580

Open
technowhizz wants to merge 1 commit into
mainfrom
sre
Open

technowhizz wants to merge 1 commit into
mainfrom
sre

Conversation

@technowhizz

Copy link
Copy Markdown
Contributor

No description provided.

@technowhizz
technowhizz requested a review from a team as a code owner October 8, 2026 16:06
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: stackhpc/stackhpc-release-train/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 397e4815-0f98-4f5d-bf57-5a7f97ea0835
📥 Commits

Reviewing files that changed from the base of the PR and between 74aba98 and 93245d5.

📒 Files selected for processing (5)
  • ansible/inventory/group_vars/all/source-repositories
  • terraform/github/branches.tf
  • terraform/github/teams.tf
  • terraform/github/terraform.tfvars.json
  • terraform/github/variables.tf

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Adds a closed SRE team and assigns it the terraform-cloudflare-dns and terraform-cloudflare-iam repositories. Grants the team push access, applies branch protection to each repository’s default branch, and adds SRE CODEOWNERS files.

Walkthrough

The change adds an SRE team and registers two Cloudflare Terraform repositories. It assigns SRE CODEOWNERS to both repositories, grants the SRE team push access, and configures branch protection for SRE repositories.

Changes

SRE team and repository setup

Layer / File(s) Summary
SRE team and repository configuration
terraform/github/variables.tf, terraform/github/terraform.tfvars.json
The default configuration adds an SRE repository list and team settings. The concrete configuration lists two repositories and the SRE team members.
Repository registration and CODEOWNERS
ansible/inventory/group_vars/all/source-repositories
The two Terraform repositories are registered as single-branch repositories with no workflows. Both use the SRE CODEOWNERS content.
Repository access and branch protection
terraform/github/teams.tf, terraform/github/branches.tf
The SRE team receives push access to its configured repositories. SRE repositories receive branch protection on their default branches.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Merge Risk: ⚪ Minimal · up to 93245

The configured SRE members can merge approved changes, and no required checks are missing. No actionable merge risk remains after normal checks.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@stackhpc-ci

Copy link
Copy Markdown
Contributor

Terraform Format and Style 🖌success

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Validation Output

Success! The configuration is valid.


Terraform Plan 📖success

Show Plan

undefined

Pusher: @technowhizz, Action: pull_request, Working Directory: ``, Workflow: Terraform GitHub

@priteau
priteau requested a review from axelsimon October 8, 2026 16:27

@Alex-Welsh Alex-Welsh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think I really have the authority to create new teams. That's something for @priteau et al to decide. I can provide some thoughts on this though.

I have a few questions about this, namely:

  • what's the scope of this new team and where do we draw a line between this and the release train?
  • where is the TF state for these new repos going to go?
  • How does this fit in with the impending infra sub-teams reshuffle?

I think that last point might be the most important one. We're planning on formalising the teams better soon, so maybe for now we just leave the repos outside of release train management, and bring them in once ownership is decided?

Comment on lines +317 to +324
"maintainers": [
"oneswig"
],
"members": [
"axelsimon",
"priteau",
"technowhizz"
]

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

4 team members is a bit low to me, especially as Stig, Axel, and Pierre all have busy management roles as well. Might be worth adding a few more members. @jackhodgkiss and @mnasiadka at the very least I think.

@priteau

priteau commented Oct 9, 2026

Copy link
Copy Markdown
Member

Based on our initial discussion of this team, the goal was to define a team overseeing our permanent, Internet-facing infrastructure: website, wiki, DNS… It might cover access to the Ark host, but the management of Pulp is delegated to the release train team.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants