Give Binjovi access to the remaining repository policies #343

Merged
binjovi-bot merged 1 commit from feat/service-policy-handoff into trunk 2026-09-06 13:23:34 +00:00
Owner

The service reader cannot inspect Linux and Pipelines protection rules because its existing account lacks repository admin access. Grant binjovi-operator-bot admin access to those two repositories, with Retain lifecycle, through the existing Forgejo user bootstrap. The Binjovi workload receives no site-admin credential.

Extend the service worker’s read-only legacy guard to the exact 64 branch and 31 tag CR names needed for the complete policy handoff. Existing Bytey hook checks remain. No protection or CI ownership changes in this prerequisite.

Validation: the expanded handoff contract fails before the grants and passes after them; the full Binjovi source guard and both affected Kustomize components pass. Live reads identified exactly these two missing grants among the 30 policy repositories.

The service reader cannot inspect Linux and Pipelines protection rules because its existing account lacks repository admin access. Grant binjovi-operator-bot admin access to those two repositories, with Retain lifecycle, through the existing Forgejo user bootstrap. The Binjovi workload receives no site-admin credential. Extend the service worker’s read-only legacy guard to the exact 64 branch and 31 tag CR names needed for the complete policy handoff. Existing Bytey hook checks remain. No protection or CI ownership changes in this prerequisite. Validation: the expanded handoff contract fails before the grants and passes after them; the full Binjovi source guard and both affected Kustomize components pass. Live reads identified exactly these two missing grants among the 30 policy repositories.
feat: grant Binjovi access for repository policy handoffs
All checks were successful
binjovi/ci Binjovi completed the frozen plan
b8018f2d1f
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/seanfarm!343
No description provided.