Skip to content

Conversation

@gastaldi
Copy link
Member

@gastaldi gastaldi commented Jan 5, 2026

  • Add Terraform configuration for creating and managing the "quarkus-redoc" repository with appropriate team permissions and branch protections.
  • Establish code ownership for the repository's Terraform script under the "quarkiverse-redoc" team.
  • Implement security and compliance measures like restricted access, pull request reviews, and bypass rules for CI integrations.
  • Fixes Redoc support for OpenAPI quarkusio/quarkus#13643

- Add Terraform configuration for creating and managing the "quarkus-redoc" repository with appropriate team permissions and branch protections.
- Establish code ownership for the repository's Terraform script under the "quarkiverse-redoc" team.
- Implement security and compliance measures like restricted access, pull request reviews, and bypass rules for CI integrations.
@github-actions
Copy link

github-actions bot commented Jan 5, 2026

Terraform Format and Style 🖌success

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Validation Output

Success! The configuration is valid.


Terraform Plan 📖success

Running plan in the remote backend. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.

Preparing the remote plan...

The remote workspace is configured to work with configuration at
terraform-scripts relative to the target repository.

Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/quarkiverse-devops/quarkiverse-devops/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
    /home/runner/work/quarkiverse-devops/quarkiverse-devops

To view this run in a browser, visit:
https://app.terraform.io/app/quarkiverse/quarkiverse-devops/runs/run-s3YXxSgoz1RLYSqe

Waiting for the plan to start...

Terraform v1.13.5
on linux_amd64
Initializing plugins and modules...

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # github_repository.quarkus_redoc will be created
  + resource "github_repository" "quarkus_redoc" {
      + allow_auto_merge            = false
      + allow_merge_commit          = true
      + allow_rebase_merge          = true
      + allow_squash_merge          = true
      + allow_update_branch         = true
      + archive_on_destroy          = true
      + archived                    = false
      + default_branch              = (known after apply)
      + delete_branch_on_merge      = true
      + description                 = "OpenAPI/Swagger-generated API Reference Documentation"
      + etag                        = (known after apply)
      + full_name                   = (known after apply)
      + git_clone_url               = (known after apply)
      + has_issues                  = true
      + homepage_url                = "https://docs.quarkiverse.io/quarkus-redoc/dev"
      + html_url                    = (known after apply)
      + http_clone_url              = (known after apply)
      + id                          = (known after apply)
      + merge_commit_message        = "PR_TITLE"
      + merge_commit_title          = "MERGE_MESSAGE"
      + name                        = "quarkus-redoc"
      + node_id                     = (known after apply)
      + primary_language            = (known after apply)
      + private                     = (known after apply)
      + repo_id                     = (known after apply)
      + squash_merge_commit_message = "COMMIT_MESSAGES"
      + squash_merge_commit_title   = "COMMIT_OR_PR_TITLE"
      + ssh_clone_url               = (known after apply)
      + svn_url                     = (known after apply)
      + topics                      = [
          + "quarkus-extension",
        ]
      + visibility                  = (known after apply)
      + vulnerability_alerts        = true
      + web_commit_signoff_required = false

      + security_and_analysis (known after apply)
    }

  # github_repository_ruleset.quarkus_redoc will be created
  + resource "github_repository_ruleset" "quarkus_redoc" {
      + enforcement = "active"
      + etag        = (known after apply)
      + id          = (known after apply)
      + name        = "main"
      + node_id     = (known after apply)
      + repository  = "quarkus-redoc"
      + ruleset_id  = (known after apply)
      + target      = "branch"

      + bypass_actors {
          + actor_id    = 995364
          + actor_type  = "Integration"
          + bypass_mode = "always"
        }

      + conditions {
          + ref_name {
              + exclude = []
              + include = [
                  + "~DEFAULT_BRANCH",
                ]
            }
        }

      + rules {
          + non_fast_forward              = true
          + update_allows_fetch_and_merge = false

          + pull_request {
              + dismiss_stale_reviews_on_push     = false
              + require_code_owner_review         = false
              + require_last_push_approval        = false
              + required_approving_review_count   = 0
              + required_review_thread_resolution = false
            }
        }
    }

  # github_team.quarkus_redoc will be created
  + resource "github_team" "quarkus_redoc" {
      + create_default_maintainer = false
      + description               = "redoc team"
      + etag                      = (known after apply)
      + id                        = (known after apply)
      + members_count             = (known after apply)
      + name                      = "quarkiverse-redoc"
      + node_id                   = (known after apply)
      + parent_team_id            = "5344029"
      + parent_team_read_id       = (known after apply)
      + parent_team_read_slug     = (known after apply)
      + privacy                   = "closed"
      + slug                      = (known after apply)
    }

  # github_team_membership.quarkus_redoc["Postremus"] will be created
  + resource "github_team_membership" "quarkus_redoc" {
      + etag     = (known after apply)
      + id       = (known after apply)
      + role     = "maintainer"
      + team_id  = (known after apply)
      + username = "Postremus"
    }

  # github_team_repository.quarkus_redoc will be created
  + resource "github_team_repository" "quarkus_redoc" {
      + etag       = (known after apply)
      + id         = (known after apply)
      + permission = "maintain"
      + repository = "quarkus-redoc"
      + team_id    = (known after apply)
    }

Plan: 5 to add, 0 to change, 0 to destroy.

Pusher: @gastaldi, Action: pull_request, Workflow: Terraform

@gastaldi gastaldi merged commit 61cd86c into main Jan 5, 2026
2 checks passed
@gastaldi gastaldi deleted the redoc branch January 5, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Redoc support for OpenAPI

2 participants