diff --git a/repository.tf b/repository.tf index 74db823..b79d857 100644 --- a/repository.tf +++ b/repository.tf @@ -45,10 +45,13 @@ resource "github_repository_ruleset" "default" { } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" + dynamic "bypass_actors" { + for_each = each.value.allow_actions_bypass ? [1] : [] + content { + actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions + actor_type = "Integration" + bypass_mode = "pull_request" + } } rules { @@ -82,10 +85,13 @@ resource "github_repository_ruleset" "all" { } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" + dynamic "bypass_actors" { + for_each = each.value.allow_actions_bypass ? [1] : [] + content { + actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions + actor_type = "Integration" + bypass_mode = "pull_request" + } } rules { diff --git a/variables.tf b/variables.tf index 03f7ef7..c8ab625 100644 --- a/variables.tf +++ b/variables.tf @@ -64,6 +64,7 @@ variable "repositories" { required_approvals = optional(number, 1) require_code_owner_reviews = optional(bool, false) allow_bypass_protection = optional(bool, false) + allow_actions_bypass = optional(bool, false) required_status_checks = optional(set(string), []) team_permission = map(string) collaborator_permission = optional(map(bool), {}) @@ -95,6 +96,7 @@ variable "repositories" { required_approvals : Required number of approvals to satisfy main branch protection requirements require_code_owner_reviews : Require an approved review in pull requests including files with a designated code owner allow_bypass_protection : Allow admins bypass branch protections + allow_actions_bypass : Allow an actor_type to bypass commit signing, see https://registry.terraform.io/providers/integrations/github/latest/docs/resources/repository_ruleset#actor_type-1 required_status_checks : The list of status checks to require in order to merge into main branch team_permission : A map of GitHub organization teams to grant access Key : The name of GitHub them team