This module creates following resources.
github_organization_ruleset
| Name | Version |
|---|---|
| terraform | >= 1.12 |
| github | >= 6.11 |
| Name | Version |
|---|---|
| github | >= 6.11 |
No modules.
| Name | Type |
|---|---|
| github_organization_ruleset.this | resource |
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| name | (Required) The name of the organization ruleset. | string |
n/a | yes |
| bypass_list | (Optional) A list of actors that are allowed to bypass the rules of the ruleset. Each item of bypass_list block as defined below.(Required) actor - A configuration for the actor that can bypass the ruleset. actor block as defined below.(Required) type - The type of actor that can bypass the ruleset. Can be one of RepositoryRole, Team, Integration, OrganizationAdmin, or DeployKey.(Optional) id - The ID of the actor that can bypass the ruleset. When type is OrganizationAdmin, this should be 1. For repository roles, use 1 (maintain), 2 (write), 3 (admin), 4 (read), or 5 (triage).(Optional) mode - The mode by which the actor can bypass the ruleset. Can be one of always or pull_request. Defaults to always. |
list(object({ |
[] |
no |
| conditions | (Optional) A configuration for the conditions that determine which repositories and refs the ruleset applies to. conditions block as defined below.(Optional) ref_name - A configuration for matching refs (branches or tags). Required when target is branch or tag. ref_name block as defined below.(Optional) include - A list of ref names or patterns to include. One of these patterns must match for the condition to pass. Also accepts the special values ~ALL (all refs) and ~DEFAULT_BRANCH (the default branch).(Optional) exclude - A list of ref names or patterns to exclude. The condition will not pass if any of these patterns match.(Optional) repository_name - A configuration for matching repositories by name. Conflicts with repository_ids. repository_name block as defined below.(Optional) include - A list of repository names or patterns to include. Also accepts the special value ~ALL.(Optional) exclude - A list of repository names or patterns to exclude.(Optional) protected - Whether to only include repositories with the default branch protected. Defaults to false.(Optional) repository_ids - A list of repository IDs to target. Conflicts with repository_name. |
object({ |
{} |
no |
| rules | (Optional) A configuration for the rules enforced by the ruleset. rules block as defined below.(Optional) creation - Whether to restrict the creation of matching refs. Defaults to false.(Optional) update - Whether to restrict updates to matching refs. Defaults to false.(Optional) deletion - Whether to restrict deletion of matching refs. Defaults to false.(Optional) required_linear_history - Whether to require a linear commit history, preventing merge commits. Defaults to false.(Optional) required_signatures - Whether to require commits pushed to matching refs to have verified signatures. Defaults to false.(Optional) non_fast_forward - Whether to block force pushes to matching refs. Defaults to false.(Optional) pull_request - A configuration to require a pull request before merging. pull_request block as defined below.(Optional) dismiss_stale_reviews_on_push - Whether to dismiss approving reviews when new commits are pushed. Defaults to false.(Optional) require_code_owner_review - Whether to require review from code owners. Defaults to false.(Optional) require_last_push_approval - Whether the most recent push must be approved by someone other than its author. Defaults to false.(Optional) required_approving_review_count - The number of approving reviews required before merging. Defaults to 0.(Optional) required_review_thread_resolution - Whether all review conversations must be resolved before merging. Defaults to false.(Optional) required_status_checks - A configuration to require status checks to pass before merging. required_status_checks block as defined below.(Optional) checks - A list of status checks that must pass. Each item of checks block as defined below.(Required) context - The name of the required status check.(Optional) integration_id - The ID of the GitHub App that provides the status check. Use 0 for checks not provided by an app.(Optional) strict_required_status_checks_policy - Whether the matching ref must be up to date with the base branch before merging. Defaults to false.(Optional) required_workflows - A configuration to require GitHub Actions workflows to pass before merging. required_workflows block as defined below.(Required) workflows - A list of workflows that must pass. Each item of workflows block as defined below.(Required) repository_id - The ID of the repository where the workflow is defined.(Required) path - The path to the workflow file (e.g., .github/workflows/scan.yaml).(Optional) ref - The ref of the workflow file. Defaults to the repository's default branch.(Optional) do_not_enforce_on_create - Whether to skip enforcing the workflows when a matching ref is created. Defaults to false.(Optional) required_code_scanning - A configuration to require code scanning results before merging. required_code_scanning block as defined below.(Required) tools - A list of code scanning tools that must run. Each item of tools block as defined below.(Required) tool - The name of the code scanning tool (e.g., CodeQL).(Required) alerts_threshold - The severity level at which code scanning alerts block merging. Can be one of none, errors, errors_and_warnings, or all.(Required) security_alerts_threshold - The severity level at which code scanning security alerts block merging. Can be one of none, critical, high_or_higher, medium_or_higher, or all.(Optional) branch_name_pattern - A configuration to enforce a naming pattern on branches. Only valid when target is branch. pattern block as defined below.(Optional) tag_name_pattern - A configuration to enforce a naming pattern on tags. Only valid when target is tag. pattern block as defined below.(Optional) commit_message_pattern - A configuration to enforce a pattern on commit messages. pattern block as defined below.(Optional) commit_author_email_pattern - A configuration to enforce a pattern on commit author emails. pattern block as defined below.(Optional) committer_email_pattern - A configuration to enforce a pattern on committer emails. pattern block as defined below.(Required) operator - How the pattern is matched. Can be one of starts_with, ends_with, contains, or regex.(Required) pattern - The pattern to match against.(Optional) name - A display name for the rule.(Optional) negate - Whether to negate the match (i.e., fail if the pattern matches). Defaults to false. |
object({ |
{} |
no |
| status | (Optional) The status (enforcement level) of the ruleset. Can be one of ACTIVE, EVALUATE, or DISABLED. Use EVALUATE to monitor (dry-run) which actions would be blocked without actually blocking them. Defaults to ACTIVE. |
string |
"ACTIVE" |
no |
| target | (Optional) The target of the ruleset. Can be one of branch, tag, or push. Defaults to branch. |
string |
"branch" |
no |
| Name | Description |
|---|---|
| bypass_list | The list of actors that are allowed to bypass the rules of the ruleset. |
| conditions | The conditions that determine which repositories and refs the ruleset applies to. |
| id | The ID of the organization ruleset. |
| name | The name of the organization ruleset. |
| node_id | The node ID of the organization ruleset. |
| rules | The rules enforced by the ruleset. |
| ruleset_id | The GitHub-assigned numeric ID of the organization ruleset. |
| status | The status (enforcement level) of the organization ruleset. |
| target | The target of the organization ruleset. |