From 64ffb1455c64e8635efaa3f3618002e4f1deb98f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Tue, 30 Sep 2025 14:49:56 +0200 Subject: [PATCH 1/3] Delete bypass_actors from repository.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Removed bypass_actors configuration for GitHub Actions. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/repository.tf b/repository.tf index 74db823..c3b1274 100644 --- a/repository.tf +++ b/repository.tf @@ -45,12 +45,6 @@ resource "github_repository_ruleset" "default" { } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" - } - rules { creation = true # restrict creation of default branch update = false # allows PR merges on default branch @@ -82,12 +76,6 @@ resource "github_repository_ruleset" "all" { } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" - } - rules { creation = false # do not restrict creation update = false From b12d8ac38c14ee3f1ecd5c8573c152dcf5bbc54f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Tue, 30 Sep 2025 15:01:03 +0200 Subject: [PATCH 2/3] allow_actions_bypass in variables.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Added 'allow_actions_bypass' option to branch protection settings. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- variables.tf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/variables.tf b/variables.tf index 03f7ef7..c8ab625 100644 --- a/variables.tf +++ b/variables.tf @@ -64,6 +64,7 @@ variable "repositories" { required_approvals = optional(number, 1) require_code_owner_reviews = optional(bool, false) allow_bypass_protection = optional(bool, false) + allow_actions_bypass = optional(bool, false) required_status_checks = optional(set(string), []) team_permission = map(string) collaborator_permission = optional(map(bool), {}) @@ -95,6 +96,7 @@ variable "repositories" { required_approvals : Required number of approvals to satisfy main branch protection requirements require_code_owner_reviews : Require an approved review in pull requests including files with a designated code owner allow_bypass_protection : Allow admins bypass branch protections + allow_actions_bypass : Allow an actor_type to bypass commit signing, see https://registry.terraform.io/providers/integrations/github/latest/docs/resources/repository_ruleset#actor_type-1 required_status_checks : The list of status checks to require in order to merge into main branch team_permission : A map of GitHub organization teams to grant access Key : The name of GitHub them team From c85209b3df94216119cb84cbce5d238aeac14f28 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Tue, 30 Sep 2025 15:18:52 +0200 Subject: [PATCH 3/3] Implement dynamic bypass_actors for GitHub Actions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Added dynamic bypass_actors block to handle GitHub Actions bot. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/repository.tf b/repository.tf index c3b1274..b79d857 100644 --- a/repository.tf +++ b/repository.tf @@ -45,6 +45,15 @@ resource "github_repository_ruleset" "default" { } } + dynamic "bypass_actors" { + for_each = each.value.allow_actions_bypass ? [1] : [] + content { + actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions + actor_type = "Integration" + bypass_mode = "pull_request" + } + } + rules { creation = true # restrict creation of default branch update = false # allows PR merges on default branch @@ -76,6 +85,15 @@ resource "github_repository_ruleset" "all" { } } + dynamic "bypass_actors" { + for_each = each.value.allow_actions_bypass ? [1] : [] + content { + actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions + actor_type = "Integration" + bypass_mode = "pull_request" + } + } + rules { creation = false # do not restrict creation update = false