Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 16 additions & 4 deletions github/components/publicRepo.ts
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,13 @@ export interface PublicRepoArgs {
* child resource's URN, which Pulumi would carry out as a delete and recreate.
*/
repoName?: Input<string>;
/**
* Names of the GitHub Actions checks the main ruleset requires. When neither
* this nor requiredChecks is given, the ruleset requires one check named
* `required`: a gate job at the end of the repository's CI that fails when any
* job it needs did, so the repository decides what blocks a merge by editing
* that job's needs. An empty list requires nothing.
*/
githubChecks?: Input<Input<string>[]>;
requiredChecks?: RepositoryRulesetRulesRequiredStatusChecks['requiredChecks'];
template?: RepositoryTemplate;
Expand Down Expand Up @@ -62,9 +69,9 @@ export class PublicRepo extends Repo {

const repo = this.repo;
const vulnerabilityAlerts = this.vulnerabilityAlerts;
const statusChecks = args.githubChecks
? getGitHubStatusChecks(args.githubChecks)
: getRequiredStatusChecks(args.requiredChecks);
const statusChecks = args.requiredChecks
? getRequiredStatusChecks(args.requiredChecks)
: getGitHubStatusChecks(args.githubChecks ?? defaultGitHubChecks);

const mainRuleset = new gh.RepositoryRuleset(
name,
Expand Down Expand Up @@ -103,6 +110,9 @@ export class PublicRepo extends Repo {
}
}

// The check every repository's CI ends in unless it says otherwise.
const defaultGitHubChecks = ['required'];

function getGitHubStatusChecks(
checks: PublicRepoArgs['githubChecks'],
): RepositoryRulesetRules['requiredStatusChecks'] {
Expand All @@ -123,5 +133,7 @@ function getRequiredStatusChecks(
): RepositoryRulesetRules['requiredStatusChecks'] {
if (!checks) return;

return { requiredChecks: checks };
// An empty list means no checks are required, which is the absence of the
// rule rather than a rule listing nothing.
return output(checks).apply(c => c.length > 0 ? { requiredChecks: c } : undefined);
}
1 change: 1 addition & 0 deletions github/repos.ts
Original file line number Diff line number Diff line change
Expand Up @@ -168,6 +168,7 @@ export const strata = new PublicRepo('strata', {
export const terraform2crd = new PublicRepo('terraform2crd', {
description: 'Converts Terraform provider code specs to Custom Resource Definitions (CRDs)',
topics: ['terraform', 'crd', 'kubernetes', 'codegen'],
githubChecks: [],
// Moved from gitlab.com/unmango/terraform/2crd, so the repository already exists.
repoOptions: { import: 'terraform2crd' },
});
Expand Down
Loading