forked from ScottyLabs/governance
Definition and automation of the Tech Committee's governance model
- Rust 95.2%
- Shell 4.6%
- Nix 0.2%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
thanks :D Co-authored-by: scottylabs-bot <ops+cmu-dev@scottylabs.org> Reviewed-on: ScottyLabs/governance#376 |
||
| .forgejo | ||
| crates | ||
| data | ||
| docs | ||
| schemas | ||
| tofu | ||
| .editorconfig | ||
| .editorconfig-checker.json | ||
| .gitattributes | ||
| .gitignore | ||
| atlantis.yaml | ||
| Cargo.lock | ||
| Cargo.toml | ||
| devenv.lock | ||
| devenv.nix | ||
| devenv.yaml | ||
| LICENSE-APACHE-2.0 | ||
| LICENSE-MIT | ||
| README.md | ||
| secretspec.toml | ||
| taplo.toml | ||
governance
This repository is the source of truth for the Tech Committee's governance model. It declaratively manages teams, repositories, and membership using OpenTofu and Atlantis.
Joining a team
- Link all available accounts in Keycloak. The only one that is optional is Codeberg.
- Add your git.cmu.dev username to the
membersarray in the desired team.tomlfile underdata/. You can find the repo here - Open a PR using a conventional PR title. You will likely need to first setup your SSH key as described in ssh-setup.md.
Note that only team leads are allowed to modify other people's memberships.
Creating a team
Teams are groups of leads, members, repositories, and channels. They can nest sub-projects recursively, each with the same shape. Copy an existing file in data/teams/ for a working starting point.
Reference the team schema for an authoritative list of fields and their constraints.
Features
See Enabling Features in the kennel docs.
Description
The following is a list of platforms Governance manages:
- Keycloak
- Members are added to their team's Keycloak groups, which gives them permission to access environment variables and other project-specific resources
- Team leads are further added to the team's admins subgroup, which gives additional access
- For projects with it enabled, OIDC clients are provisioned
- Groups a repository lists under
oidc_clientare created with their members left to be managed in Keycloak
- OpenBao
- Keycloak groups are given the appropriate access to secret paths on OpenBao
- git.cmu.dev
- Members are added to their Forgejo teams, which gives them appropriate access to the team's repositories
- Forgejo repositories are set up to automatically sync to GitHub for visibility
- Google
- Members are automatically added to ScottyLabs' and Tech's mailing lists (Google Groups)
- Members of teams with a Play Console app are given appropriate access to it
- Sentry
- Projects are provisioned under Sentry
- PostHog
- Projects are provisioned under PostHog for product analytics
- Leads of teams with a PostHog project are invited as organization members, and devops as owners
- LiteLLM
- Repositories with the AI gateway enabled receive budgeted API keys under their team, written to OpenBao per profile
- Kennel
- Repositories automatically receive a deploy webhook that authorizes them to be deployed by kennel
- Website
- Groups with a
public_urlare published to the scottylabs.org project catalog
- Groups with a
- Discord and Slack
- Members are added to the appropriate channels on both platforms
- On Discord, members are assigned the Tech role and their team's roles, and team leads additionally receive the Tech Lead role
- Bidirectional sync is established between registered Discord and Slack channels via Matrix
Here, "appropriate access" serves to delineate between member permissions and team lead permissions.