Governance
This repository is the source of truth for the Tech Committee’s governance model. It declaratively manages teams, repositories, and membership using OpenTofu and Atlantis.
Joining a team
- Link all available accounts in Keycloak. The only one that is optional is Codeberg.
- Add your git.cmu.dev username to the
membersarray in the desired team.tomlfile underdata/. You can find the repo here - Open a PR using a conventional PR title. You will likely need to first setup your SSH key as described in ssh-setup.md.
Note that only team leads are allowed to modify other people’s memberships.
Creating a team
Teams are groups of leads, members, repositories, and channels. They can nest sub-projects recursively, each with the same shape. Copy an existing file in data/teams/ for a working starting point.
Reference the team schema for an authoritative list of fields and their constraints.
Features
See Enabling Features in the kennel docs.
Description
The following is a list of platforms Governance manages:
- Keycloak
- Members are added to their team’s Keycloak groups, which gives them permission to access environment variables and other project-specific resources
- Team leads are further added to the team’s admins subgroup, which gives additional access
- For projects with it enabled, OIDC clients are provisioned
- Groups a repository lists under
oidc_clientare created with their members left to be managed in Keycloak
- OpenBao
- Keycloak groups are given the appropriate access to secret paths on OpenBao
- git.cmu.dev
- Members are added to their Forgejo teams, which gives them appropriate access to the team’s repositories
- Forgejo repositories are set up to automatically sync to GitHub for visibility
- Google
- Members are automatically added to ScottyLabs’ and Tech’s mailing lists (Google Groups)
- Members of teams with a Play Console app are given appropriate access to it
- Sentry
- Projects are provisioned under Sentry
- PostHog
- Projects are provisioned under PostHog for product analytics
- Leads of teams with a PostHog project are invited as organization members, and devops as owners
- LiteLLM
- Repositories with the AI gateway enabled receive budgeted API keys under their team, written to OpenBao per profile
- Kennel
- Repositories automatically receive a deploy webhook that authorizes them to be deployed by kennel
- Website
- Groups with a
public_urlare published to the scottylabs.org project catalog
- Groups with a
- Discord and Slack
- Members are added to the appropriate channels on both platforms
- On Discord, members are assigned the Tech role and their team’s roles, and team leads additionally receive the Tech Lead role
- Bidirectional sync is established between registered Discord and Slack channels via Matrix
Here, “appropriate access” serves to delineate between member permissions and team lead permissions.