GitHub's built-in CODEOWNERS only supports a hard "block until a team member reviews" rule, with no way to leave an audit trail when the requirement is intentionally bypassed. Move review enforcement to palantir/policy-bot (https://github.com/palantir/policy-bot) running at https://policybot.corp.ts.net, which lets us express the same tailcfg/ -> control-protocol-owners rule plus an explicit override: any other @tailscale/dev member can post policybot-override: <reason> as a PR comment and that comment counts as their approval, with the reason recorded in the PR conversation as a permanent audit trail. CODEOWNERS is kept as a one-screen comment so anyone landing on it expecting the old behavior is directed to .policy.yml. Updates tailscale/corp#13972 Change-Id: I2dc3619c498d4c4a6decae29aa123f6d67905eed Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
58 lines
1.8 KiB
YAML
58 lines
1.8 KiB
YAML
# Approval policy for this repository, enforced by policy-bot
|
|
# (https://github.com/palantir/policy-bot) running at
|
|
# https://policybot.corp.ts.net.
|
|
#
|
|
# This file replaces the role GitHub's CODEOWNERS played: when a pull
|
|
# request touches a path covered by a rule below, policy-bot posts a
|
|
# status check that blocks merging until the required reviewers approve.
|
|
#
|
|
# Policy and rule syntax reference:
|
|
# https://github.com/palantir/policy-bot/blob/develop/README.md
|
|
# Example policy files (team-approval, disapproval, remote, etc.):
|
|
# https://github.com/palantir/policy-bot/tree/develop/config/policy-examples
|
|
#
|
|
# Do not add to this policy without wide discussion.
|
|
# See https://github.com/tailscale/corp/issues/13972.
|
|
|
|
policy:
|
|
approval:
|
|
- or:
|
|
- tailcfg changes approved by control-protocol-owners
|
|
- tailcfg changes overridden by another tailscale/dev
|
|
|
|
approval_rules:
|
|
- name: tailcfg changes approved by control-protocol-owners
|
|
if:
|
|
changed_files:
|
|
paths:
|
|
- "^tailcfg/"
|
|
requires:
|
|
count: 1
|
|
teams:
|
|
- "tailscale/control-protocol-owners"
|
|
|
|
- name: tailcfg changes overridden by another tailscale/dev
|
|
description: |
|
|
Any member of @tailscale/dev (other than the PR author) can
|
|
override the control-protocol-owners requirement by leaving a
|
|
comment of the form
|
|
|
|
policybot-override: <reason>
|
|
|
|
on the pull request. The reason can be anything but should
|
|
explain why the override is appropriate; it stays in the PR
|
|
conversation as a record. The override comment also counts as
|
|
that developer's approval.
|
|
if:
|
|
changed_files:
|
|
paths:
|
|
- "^tailcfg/"
|
|
requires:
|
|
count: 1
|
|
teams:
|
|
- "tailscale/dev"
|
|
options:
|
|
methods:
|
|
comment_patterns:
|
|
- '^policybot-override: \S.*'
|