gh extensions require the executable be named exactly 'gh-<name>'
with no extension. Rename the script to match and remove the now
redundant no-extension wrapper.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The extension now uploads GitHub Actions secrets — at the repo level
and per environment — sourced from tfvars-style files of the form:
NAME = "value"
For each parsed key, the wrapper config gets its own:
- variable "<id>" { type = string, sensitive = true }
- github_actions_secret / github_actions_environment_secret
Iterating per-key (rather than passing a single map(string) into the
module with for_each) keeps every value end-to-end sensitive: it is
never used as a for_each key, never needs nonsensitive() to strip the
sensitivity marker, and never appears in plan output.
Values are passed via a temporary tfvars file written to /dev/shm
(when available) under a chmod 700 dir, cleaned by an EXIT trap.
Module:
- environments_by_name output: callers can express dependencies on
a specific env (the env-secret resources reference it so envs
are created before their secrets).
- repository_name output: stable forward-reference to the repo
short name from the wrapper.
Also adds a no-extension 'gh-repo-bootstrap' shim that execs the
'.sh' script, since 'gh' looks for executables named exactly
'gh-<name>' and the previous rename to '.sh' broke extension load.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Lets callers grant ruleset-bypass to specific actors (e.g. the Admin
repo role for solo maintainers who'd otherwise be unable to merge their
own PRs under required_reviews>=1).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>