Skip to content

feat(offboard): split GitHub and OpenShift audits - #5

Merged
DerekRoberts merged 10 commits into
mainfrom
feat/offboard-split
Sep 30, 2026
Merged

DerekRoberts merged 10 commits into
mainfrom
feat/offboard-split

Conversation

@DerekRoberts

Copy link
Copy Markdown
Member

Split the offboarding audit so a long list of people is fetched once per system, and a deleted GitHub login does not abort the report.

Summary

  • offboard-github.sh audits GitHub. Organization members are one list per org, teams are one GraphQL call per org, and code search and assignees run in batches of six (GitHub allows five ORs). Review requests stay one query per live login.
  • A login GitHub does not have is printed in that person's section and summarized at the end. The other logins still run, and the missing login is not queried.
  • offboard-openshift.sh audits RoleBindings. A GitHub id matches that id and id@github. --email matches the address only. --idir matches NAME and NAME@idir. Each input is its own section, and RoleBindings are read once per namespace.

Test plan

  • bats offboard/tests (18 tests)
  • shellcheck --severity=warning on both scripts and both bats files

A missing GitHub login is reported and skipped, and the GitHub checks that can be shared are fetched once for the whole login list.
Search queries are sent in lowercase, and a mixed-case login still matches teams, CODEOWNERS, and RoleBindings.
@DerekRoberts DerekRoberts self-assigned this Sep 29, 2026
OpenShift takes a GitHub login list and a gov.bc.ca name list. offboard.sh runs both reports, and still prints the GitHub half when oc is not logged in.
The front door no longer reads list files. One command carries every login and every gov.bc.ca name.
Search each written name as a substring so related spellings stay in one report without a suffix rule.
A grouped OR is rejected by the code search API, and that failure was discarding the repository scan already finished.
Those are leftover workflow, not leftover access, so they are out of the cleanup audit.
Drop assigned issues, CODEOWNERS code search, and environment reviewers. Keep org, teams, collaborators, CODEOWNERS files, and OpenShift.
That search finds CODEOWNERS to edit outside the admin repo set. Assigned issues and environment reviewers stay out.
List a login when it is a required reviewer on a repository environment. Team reviewers stay in the Teams section.
@DerekRoberts
DerekRoberts merged commit 08ac614 into main Sep 30, 2026
4 checks passed
@DerekRoberts
DerekRoberts deleted the feat/offboard-split branch September 30, 2026 01:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant