From 93245d54c64de9c807ac7e896e276beb1434bed8 Mon Sep 17 00:00:00 2001 From: technowhizz <7688823+technowhizz@users.noreply.github.com> Date: Thu, 8 Oct 2026 17:05:41 +0100 Subject: [PATCH] Add internal infrastructure team (SRE) --- .../group_vars/all/source-repositories | 17 ++++++++++ terraform/github/branches.tf | 31 +++++++++++++++++++ terraform/github/teams.tf | 7 +++++ terraform/github/terraform.tfvars.json | 18 +++++++++++ terraform/github/variables.tf | 9 ++++++ 5 files changed, 82 insertions(+) diff --git a/ansible/inventory/group_vars/all/source-repositories b/ansible/inventory/group_vars/all/source-repositories index 5e30bb16..04ebb69c 100644 --- a/ansible/inventory/group_vars/all/source-repositories +++ b/ansible/inventory/group_vars/all/source-repositories @@ -40,6 +40,8 @@ community_files: * @stackhpc/releasetrain sms_lab: | * @stackhpc/smslab + sre: | + * @stackhpc/sre source_repositories: # Kayobe team beokay: @@ -381,6 +383,21 @@ source_repositories: - codeowners: content: "{{ community_files.codeowners.admins }}" dest: ".github/CODEOWNERS" + # SRE team + terraform-cloudflare-dns: + repository_type: "single-branch" + workflows: [] + community_files: + - codeowners: + content: "{{ community_files.codeowners.sre }}" + dest: ".github/CODEOWNERS" + terraform-cloudflare-iam: + repository_type: "single-branch" + workflows: [] + community_files: + - codeowners: + content: "{{ community_files.codeowners.sre }}" + dest: ".github/CODEOWNERS" # Ansible team ansible-role-libvirt-host: repository_type: "ansible" diff --git a/terraform/github/branches.tf b/terraform/github/branches.tf index 739291fe..3ad9afab 100644 --- a/terraform/github/branches.tf +++ b/terraform/github/branches.tf @@ -733,3 +733,34 @@ resource "github_branch_protection" "smslab_branch_protection" { } } +resource "github_branch_protection" "sre_branch_protection" { + for_each = toset(var.repositories["SRE"]) + repository_id = data.github_repository.repositories[each.key].node_id + + pattern = data.github_repository.repositories[each.key].default_branch + require_conversation_resolution = true + allows_deletions = false + allows_force_pushes = false + + required_pull_request_reviews { + dismiss_stale_reviews = true + require_code_owner_reviews = true + required_approving_review_count = 1 + } + + restrict_pushes { + blocks_creations = false + push_allowances = [ + resource.github_team.organisation_teams["Developers"].node_id + ] + } + + required_status_checks { + contexts = lookup(var.required_status_checks, each.key, { "default" : [] }).default + strict = false + } + + lifecycle { + prevent_destroy = true + } +} diff --git a/terraform/github/teams.tf b/terraform/github/teams.tf index e4531c37..a06b9ef7 100644 --- a/terraform/github/teams.tf +++ b/terraform/github/teams.tf @@ -74,6 +74,13 @@ resource "github_team_repository" "smslab_repositories" { permission = "push" } +resource "github_team_repository" "sre_repositories" { + for_each = toset(var.repositories["SRE"]) + team_id = resource.github_team.organisation_teams["SRE"].id + repository = each.value + permission = "push" +} + resource "github_team_membership" "team_membership" { for_each = { for element in flatten([ for team in resource.github_team.organisation_teams : [ diff --git a/terraform/github/terraform.tfvars.json b/terraform/github/terraform.tfvars.json index 5af2f056..53b1fdb0 100644 --- a/terraform/github/terraform.tfvars.json +++ b/terraform/github/terraform.tfvars.json @@ -95,6 +95,10 @@ "smslab-azimuth-config", "smslab-config", "smslab-kayobe-config" + ], + "SRE": [ + "terraform-cloudflare-dns", + "terraform-cloudflare-iam" ] }, "teams": { @@ -305,6 +309,20 @@ "seunghun1ee" ] } + }, + "SRE": { + "description": "Team responsible for internal infrastructure", + "privacy": "closed", + "users": { + "maintainers": [ + "oneswig" + ], + "members": [ + "axelsimon", + "priteau", + "technowhizz" + ] + } } }, "labels": [ diff --git a/terraform/github/variables.tf b/terraform/github/variables.tf index 4223a274..21244849 100644 --- a/terraform/github/variables.tf +++ b/terraform/github/variables.tf @@ -27,6 +27,7 @@ variable "repositories" { "Platform" = [], "ReleaseTrain" = [], "SMSLab" = [], + "SRE" = [], } } @@ -104,6 +105,14 @@ variable "teams" { members = [], } }, + "SRE" = { + description = "Team responsible for internal infrastructure" + privacy = "closed" + users = { + maintainers = [], + members = [], + } + }, } }