5 Commits
Author SHA1 Message Date
Jason RossandCopilot 4cc80343c8 Rename gh-repo-bootstrap.sh -> gh-repo-bootstrap, drop shim
gh extensions require the executable be named exactly 'gh-<name>'
with no extension. Rename the script to match and remove the now
redundant no-extension wrapper.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-29 19:07:59 -05:00
Jason RossandCopilot d5707ccfeb Add --upload-repo-secrets and --upload-env-secrets
The extension now uploads GitHub Actions secrets — at the repo level
and per environment — sourced from tfvars-style files of the form:

    NAME = "value"

For each parsed key, the wrapper config gets its own:
  - variable "<id>" { type = string, sensitive = true }
  - github_actions_secret / github_actions_environment_secret

Iterating per-key (rather than passing a single map(string) into the
module with for_each) keeps every value end-to-end sensitive: it is
never used as a for_each key, never needs nonsensitive() to strip the
sensitivity marker, and never appears in plan output.

Values are passed via a temporary tfvars file written to /dev/shm
(when available) under a chmod 700 dir, cleaned by an EXIT trap.

Module:
  - environments_by_name output: callers can express dependencies on
    a specific env (the env-secret resources reference it so envs
    are created before their secrets).
  - repository_name output: stable forward-reference to the repo
    short name from the wrapper.

Also adds a no-extension 'gh-repo-bootstrap' shim that execs the
'.sh' script, since 'gh' looks for executables named exactly
'gh-<name>' and the previous rename to '.sh' broke extension load.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-29 19:06:16 -05:00
Jason Ross 944bf5e452 name file correctly 2026-04-29 18:41:06 -05:00
Jason RossandCopilot c3ee04cf35 Add bypass_actors support (incl. --solo shortcut)
Lets callers grant ruleset-bypass to specific actors (e.g. the Admin
repo role for solo maintainers who'd otherwise be unable to merge their
own PRs under required_reviews>=1).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-29 18:35:00 -05:00
Jason RossandCopilot e805082346 Initial commit: OpenTofu module + gh extension
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-29 18:28:49 -05:00