Transfer repository access grants to Binjovi services #354
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/binjovi-collaborator-handoff"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Remove the 68 retained Binjovi collaborator declarations after the service provider takes over their desired permissions. Add a bounded create-only bootstrap for the 32 management admin grants, which breaks the initial-access dependency on an empty cluster while preserving every existing grant. Accounts and token issuers keep their current ownership.
The exact legacy GET grants remain. Binjovi owns runtime permission updates, direct grant removal, and drift repair; legacy Pipeline bot grants remain with the project migration owners.
Validation: both affected components render; the source handoff and Binjovi guards pass. Bootstrap tests cover existing/missing/mixed grants, access and identity failures, and a lost PUT response with read-before-retry. The complete repository guard suite is running.
Delivery order: core Binjovi PR843 verified in production, then this source release, bootstrap success, and exact-UID retirement of the retained live CRs. Seanfarm PR352 already delivered the Retain and reader prerequisite.
9b5ff8f59a00dc06ec1900dc06ec19d9927ec196