Skip to content

Extend overture-releaser GitHub App with Actions:write and install on OvertureMaps/docs #689

Description

@lowlydba

Manual prerequisite for #679, refs OvertureMaps/docs#493. docs-publish.yml (added in #690) dispatches a production docs rebuild on OvertureMaps/docs when an overture-schema release publishes, but no app installed on this org can currently call another repo's Actions API.

What to do

Extend the existing overture-releaser app (org settings: https://github.com/organizations/OvertureMaps/settings/apps/overture-releaser) rather than provisioning a new one:

  1. Add repository permission Actions: write to overture-releaser (it currently has contents: write only, used by release-trigger.yaml, see Provision overture-release-publisher GitHub App for Phase 3 release publishing #637).
  2. Install overture-releaser additionally on OvertureMaps/docs (it's schema-repo-only today).

No new secrets are needed: docs-publish.yml reuses the same PEM already in AWS Secrets Manager (omf-github-terraform/releaser/pem, secret RELEASE_PUBLISHER_APP_PEM, read via the gha-releaser-secrets-reader OIDC role) and the same client ID (Iv23lijru2e660v1zJQO) that release-trigger.yaml already uses, just requesting permission-actions: write instead of permission-contents: write when minting the installation token.

Note

This deliberately bends omf-github-terraform/docs/github-apps.md's "one app per concern" convention (widening overture-releaser instead of provisioning a narrower new app). That's an explicit call by the user to avoid app sprawl for a second release-triggered automation on the same repo, not an oversight.

Done when

  • overture-releaser has Actions: write added in its org app settings
  • overture-releaser is installed on OvertureMaps/docs
  • The next overture-schema release confirms docs-publish.yml successfully dispatches production_deploy_documentation.yml on OvertureMaps/docs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions