Exception request: Allow FreeIPA organization on Fedora Forge #575

Closed
opened 2026-07-27 09:23:09 +00:00 by ryanlerch · 14 comments
Owner

We have received a request to create a FreeIPA organization on Fedora Forge (forge/forge#682).

FreeIPA does not strictly fall under the current Forge scope definition of "Software projects conceptualized and developed primarily to serve the Fedora community (e.g., Fedora Badges, Bodhi, fedora-messaging, etc.)." — it is an upstream project with a broader user base beyond Fedora.

However, the Forge announcement blog post explicitly notes that "Foundational ecosystem tools like Koji or FreeIPA may qualify for exceptions via a ticket request." This ticket is that request.

FreeIPA is a critical piece of software used daily in Fedora Infrastructure as the foundation of Fedora Accounts. It has a similar relationship to Fedora as Koji does — Koji also had its repositories on Pagure and now has an organization on Forge. Granting the same accommodation to FreeIPA would be consistent with that precedent.

Additionally, FreeIPA recently moved from Pagure to Codeberg, but Codeberg has since decided to ban AI-assisted software, which means FreeIPA-related projects need a new home.

Requesting Council approval for this exception to the current Forge scope.

We have received a request to create a FreeIPA organization on Fedora Forge ([forge/forge#682](https://forge.fedoraproject.org/forge/forge/issues/682)). FreeIPA does not strictly fall under the current Forge scope definition of "Software projects conceptualized and developed primarily to serve the Fedora community (e.g., Fedora Badges, Bodhi, fedora-messaging, etc.)." — it is an upstream project with a broader user base beyond Fedora. However, the [Forge announcement blog post](https://communityblog.fedoraproject.org/the-forge-is-our-new-home/) explicitly notes that "Foundational ecosystem tools like Koji or FreeIPA may qualify for exceptions via a ticket request." This ticket is that request. FreeIPA is a critical piece of software used daily in Fedora Infrastructure as the foundation of Fedora Accounts. It has a similar relationship to Fedora as Koji does — Koji also had its repositories on Pagure and now has an organization on Forge. Granting the same accommodation to FreeIPA would be consistent with that precedent. Additionally, FreeIPA recently moved from Pagure to Codeberg, but Codeberg has since decided to ban AI-assisted software, which means FreeIPA-related projects need a new home. Requesting Council approval for this exception to the current Forge scope.
Owner

+1 to approve this exception. I'm not thrilled about auth/crypto software that "mostly consist[s] of code written by 'generative AI'" but that's a separate discussion ...

+1 to approve this exception. I'm not thrilled about auth/crypto software that "mostly consist[s] of code written by 'generative AI'" but that's a separate discussion ...
Owner

+1 to approve this exception.

+1 to approve this exception.
Owner

+1 to approve

+1 to approve

+1 for approval.
Also, could we somehow ask them to say what code was AI generated?

+1 for approval. Also, could we somehow ask them to say what code was AI generated?
jflory7 added this to the Fedora Linux 45 milestone 2026-07-27 12:35:37 +00:00
Owner

+1 to approve this exception.

+1 to approve this exception.
Owner

@niknikovsky voting is restricted to council members only, however your feedback and comments are most welcome :)

@niknikovsky voting is restricted to council members only, however your feedback and comments are most welcome :)
Owner

An open-ended question: assuming this vote passes, should we be documenting this somewhere formally? Or is this issue alone sufficient documentation?

An open-ended question: assuming this vote passes, should we be documenting this somewhere formally? Or is this issue alone sufficient documentation?

@niknikovsky it is said already in the original request at forge/forge#682.

I have a larger write-up about the initial library, synta, (https://vda.li/en/posts/2026/03/23/synta/) to explain the context. The new components that use this library include https://akamu.dev (ACME server) and https://ahdapa.dev (OAuth2/SAML2 identity provider).

Akamu and Ahdapa were presented at the Flock to Fedora 2026 conference and last week Akamu interop results were presented at the IETF 126 PLANTS working group meeting as it is one of very few working implementations of Merkle Tree Certificates for both client and server sides.

@niknikovsky it is said already in the original request at https://forge.fedoraproject.org/forge/forge/issues/682. I have a larger write-up about the initial library, synta, (https://vda.li/en/posts/2026/03/23/synta/) to explain the context. The new components that use this library include https://akamu.dev (ACME server) and https://ahdapa.dev (OAuth2/SAML2 identity provider). Akamu and Ahdapa were presented at the [Flock to Fedora 2026 conference](https://cfp.fedoraproject.org/flock-to-fedora-2026/talk/KCZFQV/) and last week Akamu [interop results were presented](https://akamu.dev/blog/ietf-126-plants-presentation/) at the IETF 126 PLANTS working group meeting as it is one of very few working implementations of Merkle Tree Certificates for both client and server sides.
Owner

+1 to approve this exception

+1 to approve this exception
Owner

+1 from me

+1 from me
Owner

+1 to approve the exception

+1 to approve the exception
Owner

+1 for the exception

+1 for the exception
Owner

+1 from me too. FreeIPA is a core part of Fedora Infrastructure.

+1 from me too. FreeIPA is a core part of Fedora Infrastructure.
Owner

Approved: (9, 0, 0)

Approved: (9, 0, 0)
Sign in to join this conversation.
No milestone
No project
No assignees
12 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
council/tickets#575
No description provided.