-
Notifications
You must be signed in to change notification settings - Fork 760
Document GitHub teams and repo access rules #3912
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Jan Dubois <jan.dubois@suse.com>
f07b1df to
6db27d2
Compare
| * All committers are members of the `@lima-vm/committers` team and have the `Maintain` role on all repos. | ||
| * All reviewers are members of the `@lima-vm/reviewers` team and have the `Triage` role on all repos. | ||
| * The `@lima-vm/maintainers` team includes both committers and reviewers, but doesn't grant any extra access. | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we need to mention the org owners? (including caniszczyk and thelinuxfoundation)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think so. Ultimately the org owner is the CNCF. How the maintenance of the org is delegated by CNCF is not really part of the Lima governance but CNCF governance, imo.
| Access control is enforced via GitHub team membership: | ||
| * All committers are members of the `@lima-vm/committers` team and have the `Maintain` role on all repos. | ||
| * All reviewers are members of the `@lima-vm/reviewers` team and have the `Triage` role on all repos. | ||
| * The `@lima-vm/maintainers` team includes both committers and reviewers, but doesn't grant any extra access. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The teams are only visible to the org members.
If @rata wants to confirm the teams, we have to invite him to the org.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We can do this, if he wants. But this is due-diligence to check that actual practices match documented practices, not an audit.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The teams are only visible to the org members.
If @rata wants to confirm the teams, we have to invite him to the org.
Did you mean @rochaporto?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Did you mean @rochaporto?
Yes, sorry 🙇♂️
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No need, thanks.
AkihiroSuda
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
Ref #3795 (comment)