Skip to content

lab-aiac: activate branch protection + security scans (flip to public / upgrade plan) #196

Description

@oblinder

Context

rossoctl/lab-aiac (extracted from cortex/aiac/) is private in the
rossoctl org, which is on the Free plan. On Free, protected branches,
rulesets, and GitHub Advanced Security are gated on private repos — so branch
protection cannot be applied today (API returns 403: Upgrade to Pro or make this repository public).

Decision: flip the repo to public (planned for later). This issue records
exactly what happens automatically on that flip and what still needs a manual
step, so nothing is missed.

✅ Auto-activates on flip — no action needed

These workflow jobs are gated if: ${{ !github.event.repository.private }}
and simply start running on their next trigger after the repo is public
(they do not run retroactively on the current HEAD):

  • CodeQL (security-scans.yaml) — Python + Java-Kotlin matrix. Free for
    public repos (no GHAS purchase). Runs on next PR / push to main.
  • Dependency Review (security-scans.yaml) — needs the dependency graph,
    which is on by default for public repos. Runs on next PR.
  • OpenSSF Scorecard (scorecard.yaml) — runs on next push to main and
    on its weekly schedule.

Unaffected by visibility (already running on private): CI (lint / Python
Tests / Keycloak SPI), Dependabot, pr-verifier, docs-ci, build.

🔧 Manual steps required after the flip

  1. Apply branch protection — this is the one thing that will NOT happen on
    its own.
    Going public only removes the 403; the protection rule still
    has to be created. The rossoctl-style config is prepared and ready to PUT:

    • 1 required PR review (required_approving_review_count: 1)
    • required status checks: lint (3.12), Python Tests, Keycloak SPI (Java)
    • admins not enforced; force-push and deletion off; strict: false
    • (All three required checks are verified green.)
  2. Secret scanning + push protection (optional, free on public) are repo
    Settings toggles
    (Settings → Code security), not controlled by the
    workflow files. Enable them there if wanted — the flip alone won't turn them
    on.

⚠️ Before flipping

  • All 501 commits of history become permanently public and can be
    forked/cached/indexed even if visibility is later reverted. Run a
    full-history secret scan
    (gitleaks / trufflehog) before the flip.
  • CODEOWNERS teams (@rossoctl/maintainers, @rossoctl/platform) only
    matter if code-owner-required review is later enabled — the prepared
    protection config has that off, so not a blocker now.

Alternative to going public

Upgrade the rossoctl org to GitHub Team (~$4/user/mo) — unlocks branch
protection, rulesets, and GHAS on private repos, so the repo can stay
private. Either path ends with step 1 above (apply protection).

Acceptance

  • Full-history secret scan run and clean
  • Repo flipped to public (or org upgraded to Team)
  • Branch protection applied and verified (gh api .../branches/main/protection)
  • (optional) Secret scanning + push protection enabled
  • CodeQL / dependency-review / Scorecard observed running

Migrated from s-and-p-team/cortex#181 (opened by @oblinder on 2026-09-07). Copied to rossoctl/aiac.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions