-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathgitflow.tf
More file actions
72 lines (64 loc) · 2.9 KB
/
Copy pathgitflow.tf
File metadata and controls
72 lines (64 loc) · 2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
# Git-flow pilot wiring.
#
# A repo is git-flow when its live default branch is develop, or when its
# config/repos.yml entry sets `gitflow: true` (which wins wholesale; see
# repos.tf). local.gitflow_repos derives that set once, and everything git-flow
# reads from it: the develop branch + default-branch switch below, and the
# git-flow rulesets. Never a second list to keep in sync.
locals {
gitflow_repos = [for name, cfg in local.managed_repos : name if try(cfg.gitflow, false)]
}
# Define the custom property at the org level to tag git-flow enabled repositories
resource "github_organization_custom_properties" "gitflow" {
property_name = "gitflow"
value_type = "true_false"
}
# Attach the custom property to all gitflow repos
resource "github_repository_custom_property" "gitflow" {
for_each = toset(local.gitflow_repos)
repository = each.value
property_name = github_organization_custom_properties.gitflow.property_name
property_type = "true_false"
property_value = ["true"]
}
# develop branch, cut from main for each git-flow repo. github_branch only
# CREATES the branch — it does not reconcile later divergence — so once develop
# exists and moves ahead of main through normal git-flow work, Terraform leaves
# its ref alone. source_branch = main requires main to already exist (it does on
# every pilot repo).
resource "github_branch" "develop" {
for_each = toset(local.gitflow_repos)
repository = each.value
branch = "develop"
source_branch = "main"
}
# Adopt a develop branch that already exists.
#
# github_branch only CREATES, and a create against an existing ref 422s, so a
# git-flow repo whose live default branch is already develop is imported
# instead. Derived from the live org, never a per-repo block: an import whose
# target is already in state is a no-op, so the set can stay as wide as this.
#
# The sibling github_repository_custom_property.gitflow needs NO import: its
# create calls the GitHub CreateOrUpdateCustomProperties endpoint, so it adopts
# an already-set property value instead of failing.
import {
for_each = toset([
for name in local.gitflow_repos : name
if try(data.github_repository.enumerated[name].default_branch, "") == "develop"
])
to = github_branch.develop[each.key]
id = "${each.key}:develop"
}
# Make develop the default branch on git-flow repos: new clones and new PRs
# target the integration branch, while main is reserved for releases. The
# reference to github_branch.develop makes this depend on the branch existing
# first. Switching the default is what makes the org ~DEFAULT_BRANCH rulesets
# follow develop — which is exactly why rulesets.tf excludes git-flow repos from
# the standard default-branch rulesets and binds develop-specific rules by
# literal ref instead.
resource "github_branch_default" "develop" {
for_each = toset(local.gitflow_repos)
repository = each.value
branch = github_branch.develop[each.key].branch
}