feat(offboard): split GitHub and OpenShift audits - #5
Merged
Merged
Conversation
A missing GitHub login is reported and skipped, and the GitHub checks that can be shared are fetched once for the whole login list.
Search queries are sent in lowercase, and a mixed-case login still matches teams, CODEOWNERS, and RoleBindings.
OpenShift takes a GitHub login list and a gov.bc.ca name list. offboard.sh runs both reports, and still prints the GitHub half when oc is not logged in.
The front door no longer reads list files. One command carries every login and every gov.bc.ca name.
Search each written name as a substring so related spellings stay in one report without a suffix rule.
A grouped OR is rejected by the code search API, and that failure was discarding the repository scan already finished.
Those are leftover workflow, not leftover access, so they are out of the cleanup audit.
Drop assigned issues, CODEOWNERS code search, and environment reviewers. Keep org, teams, collaborators, CODEOWNERS files, and OpenShift.
That search finds CODEOWNERS to edit outside the admin repo set. Assigned issues and environment reviewers stay out.
List a login when it is a required reviewer on a repository environment. Team reviewers stay in the Teams section.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Split the offboarding audit so a long list of people is fetched once per system, and a deleted GitHub login does not abort the report.
Summary
offboard-github.shaudits GitHub. Organization members are one list per org, teams are one GraphQL call per org, and code search and assignees run in batches of six (GitHub allows fiveORs). Review requests stay one query per live login.offboard-openshift.shaudits RoleBindings. A GitHub id matches that id andid@github.--emailmatches the address only.--idirmatchesNAMEandNAME@idir. Each input is its own section, and RoleBindings are read once per namespace.Test plan
bats offboard/tests(18 tests)shellcheck --severity=warningon both scripts and both bats files