Skip to content

Commit 8afda04

Browse files
committed
Keep manually archived repositories archived; document renames
The deploy runs `pulumi up --refresh`, so a managed repository archived by hand in GitHub would be refreshed to archived=true and then planned back to false, un-archiving it. Ignore `archived` on the Repository resource so the manual state sticks; archiving via this config (removing the entry, which archiveOnDestroy turns into an archive) is unaffected. Also document that adding `settings` to an existing repository does not adopt it (import first), and that the `repository` key is the Pulumi resource name, so renaming it in place archives the old repository. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Kuh5eR5uDFfknR1vRPEkfn
1 parent 6fb2f2d commit 8afda04

3 files changed

Lines changed: 31 additions & 13 deletions

File tree

‎README.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,9 @@ The PR's `pulumi preview` comment shows the repository create. Once merged, the
5757
- Repository names are lowercase kebab-case (`ext-*` for extensions, `experimental-ext-*` while experimental).
5858
- At least one team or user must have `admin` permission (validated), so a managed repository is never ownerless.
5959
- Removing the entry **archives** the repository rather than deleting it; deletion stays a manual org-owner action.
60-
- Entries without `settings` are access-only: the repository pre-dates this config and Pulumi manages only its collaborators. Adopting an existing repository requires a `pulumi import` and is out of scope for the PR flow above.
60+
- Entries without `settings` are access-only: the repository pre-dates this config and Pulumi manages only its collaborators. Adding `settings` to such an entry does not adopt the repository — the deploy fails with a name-already-exists error. Adopt it with `pulumi import` first; that is out of scope for the PR flow above.
61+
- The `repository` key of a managed entry is also the Pulumi resource name. Renaming it in place archives the old repository and creates a new one: rename on GitHub first, then move the state (`pulumi state mv`) before changing the key.
62+
- A repository archived by hand in GitHub stays archived (`archived` is ignored on refresh); un-archiving is a manual org-owner action.
6163

6264
## Cloudflare Access (security-room)
6365

‎src/config/repoAccess.ts‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,13 @@ export interface RepositoryAccess {
3535
repository: string;
3636
/**
3737
* Declare to have Pulumi create and own the repository. Omit for repositories
38-
* that pre-date this config (access-only).
38+
* that pre-date this config (access-only). Adding `settings` to a repository
39+
* that already exists does not adopt it: the deploy fails with a
40+
* name-already-exists error. Adopt it with `pulumi import` first. The
41+
* `repository` key of a managed entry is also the Pulumi resource name, so
42+
* renaming it in place archives the old repository and creates a new one:
43+
* rename on GitHub first, then move the state (`pulumi state mv`) before
44+
* changing the key.
3945
*/
4046
settings?: RepositorySettings;
4147
teams?: Array<{

‎src/github.ts‎

Lines changed: 21 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -106,17 +106,27 @@ const repositories: Record<string, github.Repository> = {};
106106
REPOSITORY_ACCESS.forEach((repo) => {
107107
let repositoryName: pulumi.Input<string> = repo.repository;
108108
if (repo.settings) {
109-
const repository = new github.Repository(`repository-${repo.repository}`, {
110-
...REPOSITORY_DEFAULTS,
111-
name: repo.repository,
112-
description: repo.settings.description,
113-
visibility: repo.settings.visibility ?? 'public',
114-
homepageUrl: repo.settings.homepage,
115-
topics: repo.settings.topics ? [...repo.settings.topics] : undefined,
116-
template: repo.settings.template
117-
? { owner: GITHUB_ORG, repository: repo.settings.template }
118-
: undefined,
119-
});
109+
const repository = new github.Repository(
110+
`repository-${repo.repository}`,
111+
{
112+
...REPOSITORY_DEFAULTS,
113+
name: repo.repository,
114+
description: repo.settings.description,
115+
visibility: repo.settings.visibility ?? 'public',
116+
homepageUrl: repo.settings.homepage,
117+
topics: repo.settings.topics ? [...repo.settings.topics] : undefined,
118+
template: repo.settings.template
119+
? { owner: GITHUB_ORG, repository: repo.settings.template }
120+
: undefined,
121+
},
122+
{
123+
// A repository archived by hand in GitHub must stay archived: without
124+
// this, the deploy's `pulumi up --refresh` would plan archived: true ->
125+
// false and un-archive it. Archiving through this config still works
126+
// (remove the entry; archiveOnDestroy archives instead of deleting).
127+
ignoreChanges: ['archived'],
128+
}
129+
);
120130
repositories[repo.repository] = repository;
121131
repositoryName = repository.name;
122132
}

0 commit comments

Comments
 (0)