From 88b97c0665731563ecfec7352753ca608586fcfa Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Thu, 2 Oct 2025 10:51:15 +0200 Subject: [PATCH 01/10] exclude revoke- branches from needing signed commits MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Removed bypass_actors block and updated conditions for branch rules. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 14 +------------- 1 file changed, 1 insertion(+), 13 deletions(-) diff --git a/repository.tf b/repository.tf index 74db823..67d5c39 100644 --- a/repository.tf +++ b/repository.tf @@ -45,12 +45,6 @@ resource "github_repository_ruleset" "default" { } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" - } - rules { creation = true # restrict creation of default branch update = false # allows PR merges on default branch @@ -78,16 +72,10 @@ resource "github_repository_ruleset" "all" { conditions { ref_name { include = ["~ALL"] - exclude = [] + exclude = each.value.exclude_branches } } - bypass_actors { - actor_id = 15368 # Github Actions bot app ID was found here: https://api.github.com/apps/github-actions - actor_type = "Integration" - bypass_mode = "pull_request" - } - rules { creation = false # do not restrict creation update = false From 7d9c8cc4ac7dd8d46e8b2dc1cf53e2ae2324cddc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Thu, 2 Oct 2025 10:54:24 +0200 Subject: [PATCH 02/10] Add exclude_branches variable to variables.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- variables.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/variables.tf b/variables.tf index 03f7ef7..a9504e3 100644 --- a/variables.tf +++ b/variables.tf @@ -75,6 +75,7 @@ variable "repositories" { value = string sensitive = bool }))), {}) + exclude_branches = optional(list(string), []) })) description = <<-EOL A map of GitHub repositories in the organization. From 0c612f424582e5f20ceaa23570a176f3925450ba Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Thu, 2 Oct 2025 12:16:36 +0200 Subject: [PATCH 03/10] added required signatures ruleset --- repository.tf | 23 +++++++++++++++++++++-- variables.tf | 6 +++++- 2 files changed, 26 insertions(+), 3 deletions(-) diff --git a/repository.tf b/repository.tf index 67d5c39..52c020e 100644 --- a/repository.tf +++ b/repository.tf @@ -72,7 +72,7 @@ resource "github_repository_ruleset" "all" { conditions { ref_name { include = ["~ALL"] - exclude = each.value.exclude_branches + exclude = [] } } @@ -80,11 +80,30 @@ resource "github_repository_ruleset" "all" { creation = false # do not restrict creation update = false deletion = false - required_signatures = true non_fast_forward = false } } +resource "github_repository_ruleset" "required_signatures" { + for_each = var.repositories + + name = format("%s-%s", each.key, "required-signatures") + repository = github_repository.this[each.key].name + target = "branch" + enforcement = "active" + + conditions { + ref_name { + include = ["~ALL"] + exclude = each.value.exclude_rules.required_signatures.branches + } + } + + rules { + required_signatures = true + } +} + resource "github_repository_ruleset" "tags" { for_each = var.repositories diff --git a/variables.tf b/variables.tf index a9504e3..d723b1b 100644 --- a/variables.tf +++ b/variables.tf @@ -75,7 +75,11 @@ variable "repositories" { value = string sensitive = bool }))), {}) - exclude_branches = optional(list(string), []) + exclude_rules = optional(object({ + required_signatures = optional(object({ + branches = optional(list(string), []) + }), {}) + }), {}) })) description = <<-EOL A map of GitHub repositories in the organization. From 9b5bd6e2c9f4c134a076a6557dcdbe6bda84eefb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Mon, 6 Oct 2025 12:50:29 +0200 Subject: [PATCH 04/10] Remove required signatures ruleset from repository.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Removed the required signatures ruleset from GitHub repository configuration. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 20 -------------------- 1 file changed, 20 deletions(-) diff --git a/repository.tf b/repository.tf index 52c020e..6806ec7 100644 --- a/repository.tf +++ b/repository.tf @@ -84,26 +84,6 @@ resource "github_repository_ruleset" "all" { } } -resource "github_repository_ruleset" "required_signatures" { - for_each = var.repositories - - name = format("%s-%s", each.key, "required-signatures") - repository = github_repository.this[each.key].name - target = "branch" - enforcement = "active" - - conditions { - ref_name { - include = ["~ALL"] - exclude = each.value.exclude_rules.required_signatures.branches - } - } - - rules { - required_signatures = true - } -} - resource "github_repository_ruleset" "tags" { for_each = var.repositories From c1a44db4c82d8f2247e20a6a5297a82b75d6baea Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Mon, 6 Oct 2025 12:51:23 +0200 Subject: [PATCH 05/10] Remove exclude_rules from variables.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Removed exclude_rules and its associated structure from variables.tf. Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- variables.tf | 5 ----- 1 file changed, 5 deletions(-) diff --git a/variables.tf b/variables.tf index d723b1b..03f7ef7 100644 --- a/variables.tf +++ b/variables.tf @@ -75,11 +75,6 @@ variable "repositories" { value = string sensitive = bool }))), {}) - exclude_rules = optional(object({ - required_signatures = optional(object({ - branches = optional(list(string), []) - }), {}) - }), {}) })) description = <<-EOL A map of GitHub repositories in the organization. From 62de5440b8a2ad968669398fb17a3f68c8dd4d71 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Mon, 6 Oct 2025 12:53:26 +0200 Subject: [PATCH 06/10] Enable required signatures for repository rules all MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/repository.tf b/repository.tf index 6806ec7..c3b1274 100644 --- a/repository.tf +++ b/repository.tf @@ -80,6 +80,7 @@ resource "github_repository_ruleset" "all" { creation = false # do not restrict creation update = false deletion = false + required_signatures = true non_fast_forward = false } } From 20b2c322eae794805615eb5eac973213cf491e69 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Fri, 10 Oct 2025 10:14:27 +0200 Subject: [PATCH 07/10] add exclude_all_rules in repository.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/repository.tf b/repository.tf index c3b1274..8b7e704 100644 --- a/repository.tf +++ b/repository.tf @@ -72,7 +72,7 @@ resource "github_repository_ruleset" "all" { conditions { ref_name { include = ["~ALL"] - exclude = [] + exclude = each.value.exclude_all_rules } } From d75ae3c6d6ff04b87f02f5916535f4df774b9f0f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Fri, 10 Oct 2025 10:15:24 +0200 Subject: [PATCH 08/10] Add exclude_all_rules to variables.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- variables.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/variables.tf b/variables.tf index 03f7ef7..a3368bf 100644 --- a/variables.tf +++ b/variables.tf @@ -75,6 +75,7 @@ variable "repositories" { value = string sensitive = bool }))), {}) + exclude_all_rules = optional(list(string), []) })) description = <<-EOL A map of GitHub repositories in the organization. From 39aba44764b133142e3ee3f4ea97bc4ce17bd990 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Fri, 10 Oct 2025 10:26:37 +0200 Subject: [PATCH 09/10] Change exclude_all_rules to an optional object with branch list MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- variables.tf | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/variables.tf b/variables.tf index a3368bf..8e3bd3b 100644 --- a/variables.tf +++ b/variables.tf @@ -75,7 +75,9 @@ variable "repositories" { value = string sensitive = bool }))), {}) - exclude_all_rules = optional(list(string), []) + exclude_all_rules = optional(object({ + branches = optional(list(string), []) + }), {}) })) description = <<-EOL A map of GitHub repositories in the organization. From 9ae3ff06f05a36d73c4753d31764126fb84a5245 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Veronica=20B=2E=20Frydkj=C3=A6r?= <99909104+Rhod1um@users.noreply.github.com> Date: Fri, 10 Oct 2025 10:27:41 +0200 Subject: [PATCH 10/10] Update exclude condition to use branches in repo.tf MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Veronica B. Frydkjær <99909104+Rhod1um@users.noreply.github.com> --- repository.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/repository.tf b/repository.tf index 8b7e704..c97ab21 100644 --- a/repository.tf +++ b/repository.tf @@ -72,7 +72,7 @@ resource "github_repository_ruleset" "all" { conditions { ref_name { include = ["~ALL"] - exclude = each.value.exclude_all_rules + exclude = each.value.exclude_all_rules.branches } }