Skip to content

Conversation

@lgblaumeiser
Copy link
Contributor

Description

As explained in eclipse-tractusx/sig-infra#562

Pre-review checks

Please ensure to do as many of the following checks as possible, before asking for committer review:

Closes #eclipse-tractusx/sig-infra#562

@lgblaumeiser lgblaumeiser requested a review from a team as a code owner January 8, 2026 08:03
@eclipse-otterdog
Copy link

Thank you for raising a pull request to update the configuration of your GitHub organization.
You can manually add reviewers to this PR to eventually enable auto-merging.

The following conditions need to be fulfilled for auto-merging to be available:

  • valid configuration
  • approved by a project lead
  • does not require any secrets
  • does not update settings only accessible via the GitHub Web UI
  • does not remove any resource
Otterdog commands and options

You can trigger otterdog actions by commenting on this PR:

  • /otterdog team-info checks the team / org membership for the PR author
  • /otterdog validate validates the configuration change
  • /otterdog validate info validates the configuration change, printing also validation infos
  • /otterdog check-sync checks if the base ref is in sync with live settings
  • /otterdog merge merges and applies the changes if the PR is eligible for auto-merging (only accessible for the author)
  • /otterdog done notifies the self-service bot that a required manual apply operation has been performed (only accessible for members of the admin team)
  • /otterdog apply re-apply a previously failed attempt (only accessible for members of the admin team)

@eclipse-otterdog
Copy link

The author (lgblaumeiser) of this PR is associated with this organization in the role of MEMBER.

Additionally, lgblaumeiser is a member of the following teams:

@eclipse-otterdog

This comment has been minimized.

@eclipse-otterdog

This comment has been minimized.

Copy link
Member

@stephanbcbauer stephanbcbauer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thx @lgblaumeiser

@stephanbcbauer
Copy link
Member

managed-simple-data-exchanger-backend

I am not sure about these changes? They don't come with this PR ...

@lgblaumeiser
Copy link
Contributor Author

lgblaumeiser commented Jan 9, 2026

managed-simple-data-exchanger-backend

I am not sure about these changes? They don't come with this PR ...

They are a general configuration gap due to missing synchronization.
Obviously, the diffs are based on real world changes that are not reflected in the config file, as the last change in the file was me archiving the policy hub.

@matbmoser
Copy link
Contributor

/otterdog check-sync

@eclipse-otterdog
Copy link

Note

The current configuration is out-of-sync with the live settings:

Diff to live settings
Project automotive.tractusx[github_id=eclipse-tractusx]
  there have been 68 validation infos, enable verbose output to display them.

-  remove repo_secret[name="DOCKER_HUB_TOKEN", repository=managed-simple-data-exchanger-backend] {
-    name = "DOCKER_HUB_TOKEN"
-  }

-  remove repo_secret[name="DOCKER_HUB_USER", repository=managed-simple-data-exchanger-backend] {
-    name = "DOCKER_HUB_USER"
-  }

-  remove repo_secret[name="INT_ISSUER_SERVICE_CLIENT_ID", repository=ssi-credential-issuer] {
-    name = "INT_ISSUER_SERVICE_CLIENT_ID"
-  }

-  remove repo_secret[name="INT_ISSUER_SERVICE_CLIENT_SECRET", repository=ssi-credential-issuer] {
-    name = "INT_ISSUER_SERVICE_CLIENT_SECRET"
-  }

-  remove repo_secret[name="INT_SAP_CLIENT_ID", repository=ssi-credential-issuer] {
-    name = "INT_SAP_CLIENT_ID"
-  }

-  remove repo_secret[name="INT_SAP_CLIENT_SECRET", repository=ssi-credential-issuer] {
-    name = "INT_SAP_CLIENT_SECRET"
-  }

-  remove environment[name="ReissueExpiringCredentials", repository=ssi-credential-issuer] {
-    deployment_branch_policy = "all"
-    name                     = "ReissueExpiringCredentials"
-    reviewers                = []
-    wait_timer               = 0
-  }

  
!   repository[name="industry-core-hub"] {
!     topics = [
-      "in-development"
!     ]
!   }

  
!   repository[name="tractusx-identityhub"] {
!     description = "Eclipse Tractus-X- Identity Hub- A comprehensive DCP open source multi-dataspace wallet for
Manufacturing-X" -> null
!     homepage    = "" -> null
!     topics      = [
-      "in-development"
-      "sandbox"
!     ]
!   }

  
!   repository[name="aas-suite"] {
!     topics = [
-      "sandbox"
!     ]
!   }
  
  Plan: 0 to add, 5 to change, 7 to delete.

@matbmoser
Copy link
Contributor

/otterdog validate info

@eclipse-otterdog
Copy link

Please find below the validation of the requested configuration changes:

Diff for 5986128
Project automotive.tractusx[github_id=eclipse-tractusx]
+                                                                                                             
+ Info:   repository[name="digital-product-pass"] is archived but has branch_protection_rules which will be   
+         ignored.                                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=digital-product-pass] has                         
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                             
+ Info:   repository[name="emergingtechnologies"] is archived but has branch_protection_rules which will be   
+         ignored.                                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=emergingtechnologies] has                         
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                       
+ Info:   repo_secret[name="DEV_ADMIN_USER_API_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                       
+                                                                                                         
+ Info:   repo_secret[name="DEV_REGULAR_USER_API_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                         
+                                                                                                       
+ Info:   repo_secret[name="INT_ADMIN_USER_API_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                       
+                                                                                                         
+ Info:   repo_secret[name="INT_REGULAR_USER_API_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                         
+                                                                                                           
+ Info:   repo_secret[name="IRS_CUCUMBER_PUBLISH_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                                           
+                                                                                                   
+ Info:   repo_secret[name="SONAR_ORGANIZATION"] only has a dummy value, resource will be skipped.  
+                                                                                                   
+                                                                                                  
+ Info:   repo_secret[name="SONAR_PROJECT_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                  
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=item-relationship-service] has                    
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                           
+ Info:   repository[name="policy-hub"] is archived but has branch_protection_rules which will be ignored.  
+                                                                                                           
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=policy-hub] has 'requires_status_checks'          
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal] has 'requires_status_checks' disabled,    
+         but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']', setting will    
+         be ignored.                                                                                         
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-assets] has 'requires_status_checks'       
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-backend] has 'requires_status_checks'      
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-frontend] has 'requires_status_checks'     
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-frontend-registration] has                 
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-iam] has 'requires_status_checks'          
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                            
+ Info:   repo_secret[name="NPM_PUBLISH"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=portal-shared-components] has                     
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                            
+ Info:   repo_secret[name="NOTIFICATION_EMAIL_PASSWORD"] only has a dummy value, resource will be skipped.  
+                                                                                                            
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                              
+ Info:   repo_secret[name="CLIENT_ID_DEV"] only has a dummy value, resource will be skipped.  
+                                                                                              
+                                                                                              
+ Info:   repo_secret[name="CLIENT_ID_INT"] only has a dummy value, resource will be skipped.  
+                                                                                              
+                                                                                                  
+ Info:   repo_secret[name="CLIENT_SECRET_DEV"] only has a dummy value, resource will be skipped.  
+                                                                                                  
+                                                                                                  
+ Info:   repo_secret[name="CLIENT_SECRET_INT"] only has a dummy value, resource will be skipped.  
+                                                                                                  
+                                                                                            
+ Info:   repo_secret[name="IDP_URL_DEV"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                            
+ Info:   repo_secret[name="IDP_URL_INT"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                      
+ Info:   repo_secret[name="SEMANTIC_HUB_DEV_BASE"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                      
+ Info:   repo_secret[name="SEMANTIC_HUB_INT_BASE"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                             
+ Info:   repository[name="ssi-authority-schema-registry"] is archived but has branch_protection_rules which  
+         will be ignored.                                                                                    
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=ssi-authority-schema-registry] has                
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=ssi-credential-issuer] has                        
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                             
+ Info:   repo_secret[name="E2E_TXA_HOST"] only has a dummy value, resource will be skipped.  
+                                                                                             
+                                                                                             
+ Info:   repo_secret[name="E2E_TXB_HOST"] only has a dummy value, resource will be skipped.  
+                                                                                             
+                                                                                              
+ Info:   repo_secret[name="KEYCLOAK_HOST"] only has a dummy value, resource will be skipped.  
+                                                                                              
+                                                                                                      
+ Info:   repo_secret[name="ORG_IRS_JIRA_PASSWORD"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                      
+ Info:   repo_secret[name="ORG_IRS_JIRA_USERNAME"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                    
+ Info:   repo_secret[name="SONAR_TOKEN_BACKEND"] only has a dummy value, resource will be skipped.  
+                                                                                                    
+                                                                                                     
+ Info:   repo_secret[name="SONAR_TOKEN_FRONTEND"] only has a dummy value, resource will be skipped.  
+                                                                                                     
+                                                                                                     
+ Info:   repo_secret[name="SUPERVISOR_CLIENT_ID"] only has a dummy value, resource will be skipped.  
+                                                                                                     
+                                                                                                    
+ Info:   repo_secret[name="SUPERVISOR_PASSWORD"] only has a dummy value, resource will be skipped.  
+                                                                                                    
+                                                                                                    
+ Info:   repo_secret[name="TRACE_X_ADMIN_LOGIN"] only has a dummy value, resource will be skipped.  
+                                                                                                    
+                                                                                                 
+ Info:   repo_secret[name="TRACE_X_ADMIN_PW"] only has a dummy value, resource will be skipped.  
+                                                                                                 
+                                                                                                    
+ Info:   repo_secret[name="TRACE_X_API_KEY_DEV"] only has a dummy value, resource will be skipped.  
+                                                                                                    
+                                                                                                      
+ Info:   repo_secret[name="TRACE_X_API_KEY_INT_A"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                      
+ Info:   repo_secret[name="TRACE_X_API_KEY_INT_B"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                         
+ Info:   repo_secret[name="TRACE_X_SUPERVISOR_LOGIN"] only has a dummy value, resource will be skipped.  
+                                                                                                         
+                                                                                                      
+ Info:   repo_secret[name="TRACE_X_SUPERVISOR_PW"] only has a dummy value, resource will be skipped.  
+                                                                                                      
+                                                                                                   
+ Info:   repo_secret[name="TRACE_X_USER_LOGIN"] only has a dummy value, resource will be skipped.  
+                                                                                                   
+                                                                                                
+ Info:   repo_secret[name="TRACE_X_USER_PW"] only has a dummy value, resource will be skipped.  
+                                                                                                
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=traceability-foss] has 'requires_status_checks'   
+         disabled, but 'required_status_checks' is set to '['eclipse-eca-validation:eclipsefdn/eca']',       
+         setting will be ignored.                                                                            
+                                                                                                             
+                                                                                                             
+ Info:   repository[name="traceability-foss-backend"] is archived but has branch_protection_rules which      
+         will be ignored.                                                                                    
+                                                                                                             
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=traceability-foss-backend] has                    
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                
+ Info:   repo_secret[name="AZURE_CLIENT_ID"] only has a dummy value, resource will be skipped.  
+                                                                                                
+                                                                                                    
+ Info:   repo_secret[name="AZURE_CLIENT_SECRET"] only has a dummy value, resource will be skipped.  
+                                                                                                    
+                                                                                                
+ Info:   repo_secret[name="AZURE_TENANT_ID"] only has a dummy value, resource will be skipped.  
+                                                                                                
+                                                                                                 
+ Info:   repo_secret[name="AZURE_VAULT_NAME"] only has a dummy value, resource will be skipped.  
+                                                                                                 
+                                                                                               
+ Info:   repo_secret[name="GPG_PASSPHRASE"] only has a dummy value, resource will be skipped.  
+                                                                                               
+                                                                                                
+ Info:   repo_secret[name="GPG_PRIVATE_KEY"] only has a dummy value, resource will be skipped.  
+                                                                                                
+                                                                                            
+ Info:   repo_secret[name="SONAR_TOKEN"] only has a dummy value, resource will be skipped.  
+                                                                                            
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=tractusx-edc-kafka-extension] has                 
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             
+                                                                                                             
+ Info:   branch_protection_rule[pattern="main", repository=tractusx-edc-template] has                        
+         'requires_status_checks' disabled, but 'required_status_checks' is set to                           
+         '['eclipse-eca-validation:eclipsefdn/eca']', setting will be ignored.                               
+                                                                                                             

  
!   repository[name="ssi-authority-schema-registry"] {
!     archived = false -> true
!   }
  
  Plan: 0 to add, 1 to change, 0 to delete.

@matbmoser
Copy link
Contributor

/otterdog merge

@lgblaumeiser
Copy link
Contributor Author

/otterdog merge

@matbmoser matbmoser requested a review from kairoaraujo January 9, 2026 09:59
@matbmoser
Copy link
Contributor

Hi @kairoaraujo could you support us here?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants