Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Governance

This repository is the source of truth for the Tech Committee’s governance model. It declaratively manages teams, repositories, and membership using OpenTofu and Atlantis.

Joining a team

  1. Link all available accounts in Keycloak. The only one that is optional is Codeberg.
  2. Add your git.cmu.dev username to the members array in the desired team .toml file under data/. You can find the repo here
  3. Open a PR using a conventional PR title. You will likely need to first setup your SSH key as described in ssh-setup.md.

Note that only team leads are allowed to modify other people’s memberships.

Creating a team

Teams are groups of leads, members, repositories, and channels. They can nest sub-projects recursively, each with the same shape. Copy an existing file in data/teams/ for a working starting point.

Reference the team schema for an authoritative list of fields and their constraints.

Features

See Enabling Features in the kennel docs.

Description

The following is a list of platforms Governance manages:

  1. Keycloak
    • Members are added to their team’s Keycloak groups, which gives them permission to access environment variables and other project-specific resources
    • Team leads are further added to the team’s admins subgroup, which gives additional access
    • For projects with it enabled, OIDC clients are provisioned
    • Groups a repository lists under oidc_client are created with their members left to be managed in Keycloak
  2. OpenBao
    • Keycloak groups are given the appropriate access to secret paths on OpenBao
  3. git.cmu.dev
    • Members are added to their Forgejo teams, which gives them appropriate access to the team’s repositories
    • Forgejo repositories are set up to automatically sync to GitHub for visibility
  4. Google
    • Members are automatically added to ScottyLabs’ and Tech’s mailing lists (Google Groups)
    • Members of teams with a Play Console app are given appropriate access to it
  5. Sentry
    • Projects are provisioned under Sentry
  6. PostHog
    • Projects are provisioned under PostHog for product analytics
    • Leads of teams with a PostHog project are invited as organization members, and devops as owners
  7. LiteLLM
    • Repositories with the AI gateway enabled receive budgeted API keys under their team, written to OpenBao per profile
  8. Kennel
    • Repositories automatically receive a deploy webhook that authorizes them to be deployed by kennel
  9. Website
    • Groups with a public_url are published to the scottylabs.org project catalog
  10. Discord and Slack
    • Members are added to the appropriate channels on both platforms
    • On Discord, members are assigned the Tech role and their team’s roles, and team leads additionally receive the Tech Lead role
    • Bidirectional sync is established between registered Discord and Slack channels via Matrix

Here, “appropriate access” serves to delineate between member permissions and team lead permissions.