Context
rossoctl/lab-aiac (extracted from cortex/aiac/) is private in the
rossoctl org, which is on the Free plan. On Free, protected branches,
rulesets, and GitHub Advanced Security are gated on private repos — so branch
protection cannot be applied today (API returns 403: Upgrade to Pro or make this repository public).
Decision: flip the repo to public (planned for later). This issue records
exactly what happens automatically on that flip and what still needs a manual
step, so nothing is missed.
✅ Auto-activates on flip — no action needed
These workflow jobs are gated if: ${{ !github.event.repository.private }}
and simply start running on their next trigger after the repo is public
(they do not run retroactively on the current HEAD):
- CodeQL (
security-scans.yaml) — Python + Java-Kotlin matrix. Free for
public repos (no GHAS purchase). Runs on next PR / push to main.
- Dependency Review (
security-scans.yaml) — needs the dependency graph,
which is on by default for public repos. Runs on next PR.
- OpenSSF Scorecard (
scorecard.yaml) — runs on next push to main and
on its weekly schedule.
Unaffected by visibility (already running on private): CI (lint / Python
Tests / Keycloak SPI), Dependabot, pr-verifier, docs-ci, build.
🔧 Manual steps required after the flip
-
Apply branch protection — this is the one thing that will NOT happen on
its own. Going public only removes the 403; the protection rule still
has to be created. The rossoctl-style config is prepared and ready to PUT:
- 1 required PR review (
required_approving_review_count: 1)
- required status checks:
lint (3.12), Python Tests, Keycloak SPI (Java)
- admins not enforced; force-push and deletion off;
strict: false
- (All three required checks are verified green.)
-
Secret scanning + push protection (optional, free on public) are repo
Settings toggles (Settings → Code security), not controlled by the
workflow files. Enable them there if wanted — the flip alone won't turn them
on.
⚠️ Before flipping
- All 501 commits of history become permanently public and can be
forked/cached/indexed even if visibility is later reverted. Run a
full-history secret scan (gitleaks / trufflehog) before the flip.
- CODEOWNERS teams (
@rossoctl/maintainers, @rossoctl/platform) only
matter if code-owner-required review is later enabled — the prepared
protection config has that off, so not a blocker now.
Alternative to going public
Upgrade the rossoctl org to GitHub Team (~$4/user/mo) — unlocks branch
protection, rulesets, and GHAS on private repos, so the repo can stay
private. Either path ends with step 1 above (apply protection).
Acceptance
Migrated from s-and-p-team/cortex#181 (opened by @oblinder on 2026-09-07). Copied to rossoctl/aiac.
Context
rossoctl/lab-aiac(extracted fromcortex/aiac/) is private in therossoctlorg, which is on the Free plan. On Free, protected branches,rulesets, and GitHub Advanced Security are gated on private repos — so branch
protection cannot be applied today (API returns
403: Upgrade to Pro or make this repository public).Decision: flip the repo to public (planned for later). This issue records
exactly what happens automatically on that flip and what still needs a manual
step, so nothing is missed.
✅ Auto-activates on flip — no action needed
These workflow jobs are gated
if: ${{ !github.event.repository.private }}and simply start running on their next trigger after the repo is public
(they do not run retroactively on the current HEAD):
security-scans.yaml) — Python + Java-Kotlin matrix. Free forpublic repos (no GHAS purchase). Runs on next PR / push to
main.security-scans.yaml) — needs the dependency graph,which is on by default for public repos. Runs on next PR.
scorecard.yaml) — runs on next push tomainandon its weekly schedule.
Unaffected by visibility (already running on private): CI (lint / Python
Tests / Keycloak SPI), Dependabot, pr-verifier, docs-ci, build.
🔧 Manual steps required after the flip
Apply branch protection — this is the one thing that will NOT happen on
its own. Going public only removes the
403; the protection rule stillhas to be created. The rossoctl-style config is prepared and ready to
PUT:required_approving_review_count: 1)lint (3.12),Python Tests,Keycloak SPI (Java)strict: falseSecret scanning + push protection (optional, free on public) are repo
Settings toggles (Settings → Code security), not controlled by the
workflow files. Enable them there if wanted — the flip alone won't turn them
on.
forked/cached/indexed even if visibility is later reverted. Run a
full-history secret scan (gitleaks / trufflehog) before the flip.
@rossoctl/maintainers,@rossoctl/platform) onlymatter if code-owner-required review is later enabled — the prepared
protection config has that off, so not a blocker now.
Alternative to going public
Upgrade the
rossoctlorg to GitHub Team (~$4/user/mo) — unlocks branchprotection, rulesets, and GHAS on private repos, so the repo can stay
private. Either path ends with step 1 above (apply protection).
Acceptance
gh api .../branches/main/protection)Migrated from s-and-p-team/cortex#181 (opened by @oblinder on 2026-09-07). Copied to rossoctl/aiac.