Give Binjovi access to the remaining repository policies #343
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/service-policy-handoff"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The service reader cannot inspect Linux and Pipelines protection rules because its existing account lacks repository admin access. Grant binjovi-operator-bot admin access to those two repositories, with Retain lifecycle, through the existing Forgejo user bootstrap. The Binjovi workload receives no site-admin credential.
Extend the service worker’s read-only legacy guard to the exact 64 branch and 31 tag CR names needed for the complete policy handoff. Existing Bytey hook checks remain. No protection or CI ownership changes in this prerequisite.
Validation: the expanded handoff contract fails before the grants and passes after them; the full Binjovi source guard and both affected Kustomize components pass. Live reads identified exactly these two missing grants among the 30 policy repositories.