FAS group and Forge group for Discourse Moderation Team (in order to facilitate the necessary Docs repo) #449

Closed
opened 2026-03-08 15:59:31 +00:00 by py0xc3 · 26 comments

I would like to ask for an FAS group and a Forge group for the Discourse Moderation Team.

Theoretically, we can re-use the old ask-fedora group, but the name already suggests it's from a time before we merged our Discourse instances, so that could be confusing and the members are obsoleted along with the channels that are linked from and to the old ask-fedora group. A new FAS group thus might be less confusing. However, I think the majority of us is fine with both, and we would leave it to you to re-use the old one of create a new FAS group.

The primary reason to get an FAS group organized is to get a Forge group because we need a new repo on Forge to provide our Docs: this is linked to the recent decision & poll about the new Fedora Discussion Forum (Self-)Moderation Guidelines and Rules and where to publish them -> the decision was to use the Docs.

In both cases, I would like to ask to set the regularly-active moderators as sponsors/owners: I assume that would be @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm (I just took every person with mod privilege I found in any 2+ "top 5 poster" lists of any moderation topic of the 12 months before the poll discussion; that "definition" is just a suggestion that felt reasonable -> did I forget someone? I was not sure if @jflory7 and @jspaleta want to join there?).

Please do not auto-add all moderators/TL3/TL4, because the majority is not active on Discourse, and I would like to use this as an incentive to allow the moderation to get some "space" to distinguish themselves and develop some self-determination as a team, in order to maybe at some point (if the need exists) go beyond the daily tackling of what comes up towards preventive / strategic organizing their resources, and thus also better integrate/represent as team in the wider community, communicate their "supply & demand" etc. I see much potential to increase the value of the team and for the team itself. Hope that makes some sense :)

Let me know if there are questions or something I can do to help ;)

This is not urgent.

Thanks again to @jflory7 to provide the incentive that got this development started :)

I would like to ask for an FAS group and a Forge group for the Discourse Moderation Team. Theoretically, we can re-use the old `ask-fedora` group, but the name already suggests it's from a time before we merged our Discourse instances, so that could be confusing and the members are obsoleted along with the channels that are linked from and to the old `ask-fedora` group. A new FAS group thus might be less confusing. However, I think the majority of us is fine with both, and we would leave it to you to re-use the old one of create a new FAS group. The primary reason to get an FAS group organized is to get a Forge group because we need a new repo on Forge to provide our Docs: this is linked to the recent decision & poll about the new `Fedora Discussion Forum (Self-)Moderation Guidelines and Rules` and where to publish them -> the decision was to use the Docs. In both cases, I would like to ask to set the regularly-active moderators as sponsors/owners: I assume that would be @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm (I just took every person with mod privilege I found in any 2+ "top 5 poster" lists of any moderation topic of the 12 months before the poll discussion; that "definition" is just a suggestion that felt reasonable -> did I forget someone? I was not sure if @jflory7 and @jspaleta want to join there?). Please do not auto-add all moderators/TL3/TL4, because the majority is not active on Discourse, and I would like to use this as an incentive to allow the moderation to get some "space" to distinguish themselves and develop some self-determination as a team, in order to maybe at some point (if the need exists) go beyond the daily tackling of what comes up towards preventive / strategic organizing their resources, and thus also better integrate/represent as team in the wider community, communicate their "supply & demand" etc. I see much potential to increase the value of the team and for the team itself. Hope that makes some sense :) Let me know if there are questions or something I can do to help ;) This is not urgent. Thanks again to @jflory7 to provide the incentive that got this development started :)
Contributor

Since I have admin access on Fedora Discourse, you can keep me included as a group member and sponsor.

Happy to help @py0xc3!

Since I have admin access on Fedora Discourse, you can keep me included as a group member and sponsor. Happy to help @py0xc3!
Owner

would this be more suitable for a team and repo under commops? rather than an entirely new organization?

we can set up say a forge-commops-discoursemods team, and give them access to just the repo that is needed?

would this be more suitable for a team and repo under commops? rather than an entirely new organization? we can set up say a `forge-commops-discoursemods` team, and give them access to just the repo that is needed?
Author

It would be good to have our sponsors added to either a new or the existing FAS group.

As far as it concerns Forge, we need to add and remove ourselves the people who can merge/edit in the Docs repo. If that works with the alternative you suggested, that is fine.

It would be good to have our sponsors added to either a new or the existing FAS group. As far as it concerns Forge, we need to add and remove ourselves the people who can merge/edit in the Docs repo. If that works with the alternative you suggested, that is fine.
Owner

so yes, we can create a new group on FAS, forge-commops-discoursemoderation and link it to a new team in the comm-ops organization.

We can then give members of that team access to just the discousce moderation docs repo. (and other repos too if you add more in the future.)

The one caveat here is that currently the commops-members team is set up to have access to all repos in the org, so that would include the discourse moderation docs repos. My suggestion here is to set up the members team to have access to just a specific set of repos as well.

so yes, we can create a new group on FAS, `forge-commops-discoursemoderation` and link it to a new team in the comm-ops organization. We can then give members of that team access to just the discousce moderation docs repo. (and other repos too if you add more in the future.) The one caveat here is that currently the commops-members team is set up to have access to all repos in the org, so that would include the discourse moderation docs repos. My suggestion here is to set up the members team to have access to just a specific set of repos as well.
Author

so yes, we can create a new group on so yes, we can create a new group on FAS forge-commops-discoursemoderation

I meant that in general, have a FAS group for the Discourse team, in contrast to the current state in which the "old" FAS group ask-fedora contains mostly sponsors (and members) no longer active/available -> that is not only for the Forge group :) As I said, we don't care if we keep using the existing ask-fedora FAS group and update the sponsors, or if we create something new to avoid the confusion (-> ask-fedora no longer exists as dedicated platform). We leave that to whatever is better for you / commops / infra.

You do not need to automatically map FAS group <-> Forge repo (not every FAS group member should have MR privileges anyway!), we can do that "manually" too as long as the sponsors of the FAS group are also owners of the repo (if we have the necessary privileges and if it is easier for you, we can maintain that "state" in future manually as well). The background of our need is, one one hand, the issue that this repo is "powerful" and is published as the rules that are to be enforced for our Discourse, so we have to be careful who can merge stuff there. On the other hand, especially in the beginning (and when new developments around AI or new technologies emerge) it might be more often necessary that we adjust it, and we need to ensure that adjustments are possible by those currently active in moderation (not all mods are available at all times due to other obligations, so we need to avoid bottlenecks as some changes can be time critical -> e.g., we had such an issue with AI, when exploitation started to take place and we found out our rules are not prepared for that). The latter might also make it necessary to involve long term TL4 members or so to some extent (we do not yet know how this will develop as a big change is ongoing with us). Just to elaborate the background of our needs. Sorry for causing the confusion :)

Concerning your suggestion about Forge, that is fine for me. As long as we can add/remove people with privileges to make changes to the repo on ourselves, we are fine with whatever fits you best :)

I would ask @jflory7 though: is that fine for commops too? I don't want to "break" anything for you or so.

> so yes, we can create a new group on so yes, we can create a new group on FAS forge-commops-discoursemoderation I meant that in general, have a FAS group for the Discourse team, in contrast to the current state in which the "old" FAS group `ask-fedora` contains mostly sponsors (and members) no longer active/available -> that is not only for the Forge group :) As I said, we don't care if we keep using the existing `ask-fedora` FAS group and update the sponsors, or if we create something new to avoid the confusion (-> `ask-fedora` no longer exists as dedicated platform). We leave that to whatever is better for you / commops / infra. You do not need to automatically map FAS group <-> Forge repo (not every FAS group member should have MR privileges anyway!), we can do that "manually" too as long as the sponsors of the FAS group are also owners of the repo (if we have the necessary privileges and if it is easier for you, we can maintain that "state" in future manually as well). The background of our need is, one one hand, the issue that this repo is "powerful" and is published as the rules that are to be enforced for our Discourse, so we have to be careful who can merge stuff there. On the other hand, especially in the beginning (and when new developments around AI or new technologies emerge) it might be more often necessary that we adjust it, and we need to ensure that adjustments are possible by those currently active in moderation (not all mods are available at all times due to other obligations, so we need to avoid bottlenecks as some changes can be time critical -> e.g., we had such an issue with AI, when exploitation started to take place and we found out our rules are not prepared for that). The latter might also make it necessary to involve long term TL4 members or so to some extent (we do not yet know how this will develop as a big change is ongoing with us). Just to elaborate the background of our needs. Sorry for causing the confusion :) Concerning your suggestion about Forge, that is fine for me. As long as we can add/remove people with privileges to make changes to the repo on ourselves, we are fine with whatever fits you best :) I would ask @jflory7 though: is that fine for commops too? I don't want to "break" anything for you or so.
Owner

Sorry, what i am suggesting is that we have forge-commops-discoursemoderation group created. and we add members to that group, for example, we add these members:

@ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm

then we map that group to a new team in commops discoursemoderation team, and only people that are members in that FAS group have access to that repo.

Sorry, what i am suggesting is that we have `forge-commops-discoursemoderation` group created. and we add members to that group, for example, we add these members: @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm then we map that group to a new team in commops `discoursemoderation` team, and only people that are members in that FAS group have access to that repo.
Contributor

Wait a second – Fedora Discussion is not managed by the Fedora Community Ops Team. I don't want to conflate Discourse forum moderation with the Community Ops team, because that is not what we do.

I think we probably just need to have a Discourse/forum FAS staff group? I am not sure if we have some FAS group syncing going on there or not, but if we can leverage any other group which already exists, that would also be useful.

Wait a second – Fedora Discussion is not managed by the Fedora Community Ops Team. I don't want to conflate Discourse forum moderation with the Community Ops team, because that is not what we do. I think we probably just need to have a Discourse/forum FAS staff group? I am not sure if we have some FAS group syncing going on there or not, but if we can leverage any other group which already exists, that would also be useful.
Author

Fedora Discussion is not managed by the Fedora Community Ops Team. I don't want to conflate Discourse forum moderation with the Community Ops team, because that is not what we do.

I think we should go back to my original proposal, as the Discourse Moderation is a SIG itself and not part of another team, as you say.

Also, this is getting complex and it would be useful if the structures would be straightforward to every mod.

So, just get us either a new FAS group (Discourse-Moderation or so) or update the old one (ask-fedora), and then create a new group in Forge, ensuring the sponsors of the FAS group are the owners of the Forge group and can administrate privileges within the group.

(I have a tendency to create a new FAS and delete the old one -> it's dead and refers to a discourse that no longer exists, that can be confusing)

I am not sure if we have some FAS group syncing going on there or not

So far not, the old ask-fedora FAS that formally still exists is, as the name suggests, from the time when we had two Discourse instances. It's not connected to the current Discourse.

> Fedora Discussion is not managed by the Fedora Community Ops Team. I don't want to conflate Discourse forum moderation with the Community Ops team, because that is not what we do. I think we should go back to my original proposal, as the Discourse Moderation is a SIG itself and not part of another team, as you say. Also, this is getting complex and it would be useful if the structures would be straightforward to every mod. So, just get us either a new FAS group (`Discourse-Moderation` or so) or update the old one (`ask-fedora`), and then create a new group in Forge, ensuring the sponsors of the FAS group are the owners of the Forge group and can administrate privileges within the group. (I have a tendency to create a new FAS and delete the old one -> it's dead and refers to a discourse that no longer exists, that can be confusing) > I am not sure if we have some FAS group syncing going on there or not So far not, the old `ask-fedora` FAS that formally still exists is, as the name suggests, from the time when we had two Discourse instances. It's not connected to the current Discourse.
Owner

my bad -- my assumption that moderating the discussion forums was a commops type task. Just trying to avoid creating new orgs when they are in fact sub-teams of existing teams.

my bad -- my assumption that moderating the discussion forums was a commops type task. Just trying to avoid creating new orgs when they are in fact sub-teams of existing teams.
Owner

would this work?

  1. new fas group: forge-discussion-owners sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm
  2. another new fas group: forge-discussion-members. sponsors the list above, and members the list above + whoever else has commit access.
  3. new forge org discussion -- i chose this since it does not lock us into discourse if we change for some reason, and we might also want to store other things related to discussion other than moderation docs in the future. (this is similar to how we have the forge org already)
  4. owners team on forge has full access to the org. members team has commit access (or ticket access or whatever you want there)
would this work? 1. new fas group: `forge-discussion-owners` sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm 2. another new fas group: `forge-discussion-members`. sponsors the list above, and members the list above + whoever else has commit access. 3. new forge org `discussion` -- i chose this since it does not lock us into discourse if we change for some reason, and we might also want to store other things related to discussion other than moderation docs in the future. (this is similar to how we have the `forge` org already) 4. owners team on forge has full access to the org. members team has commit access (or ticket access or whatever you want there)
ryanlerch added this to the Sprint 16 project 2026-03-18 03:32:37 +00:00
Author

my bad

No worries. Thanks for taking care of the case :-)

new fas group: forge-discussion-owners sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm
another new fas group: forge-discussion-members. sponsors the list above, and members the list above + whoever else has commit access.
new forge org discussion -- i chose this since it does not lock us into discourse if we change for some reason, and we might also want to store other things related to discussion other than moderation docs in the future. (this is similar to how we have the forge org already)
owners team on forge has full access to the org. members team has commit access (or ticket access or whatever you want there)

Mostly, but "members" who are not owners should not have commit access in order to avoid that every individual member can change the rules that are published. So they should be able to do PR/MR, and of course everyone on forge should be able to open a ticket: I assume we can change the privileges of individual members on forge manually, so that we can add commit privileges to single members on demand, rather than generally to the whole members group, right? So the idea is to start by default without commit, and owners decide individually when a single member needs (temporarily) commit rights.

It's not a requirement, but as the FAS groups are intended for general use (not necessarily only for forge), does it make sense to remove the forge- in the name? That's more curiosity, not a "must have" :)

> my bad No worries. Thanks for taking care of the case :-) > new fas group: forge-discussion-owners sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm > another new fas group: forge-discussion-members. sponsors the list above, and members the list above + whoever else has commit access. > new forge org discussion -- i chose this since it does not lock us into discourse if we change for some reason, and we might also want to store other things related to discussion other than moderation docs in the future. (this is similar to how we have the forge org already) > owners team on forge has full access to the org. members team has commit access (or ticket access or whatever you want there) Mostly, but "members" who are **not** owners should **not** have commit access in order to avoid that every individual member can change the rules that are published. So they should be able to do PR/MR, and of course everyone on forge should be able to open a ticket: I assume we can change the privileges of individual members on forge manually, so that we can add commit privileges to single members on demand, rather than generally to the whole members group, right? So the idea is to start by default without commit, and owners decide individually when a single member needs (temporarily) commit rights. It's not a requirement, but as the FAS groups are intended for general use (not necessarily only for forge), does it make sense to remove the `forge-` in the name? That's more curiosity, not a "must have" :)
Owner

Sounds like you don't really need a members group at all.

lets just make the forge-discussion-owners map to the owners team. Then if you want to add access, you can add them to that group.

we are keeping the "forge-" prefix for all the forge permissions groups, but if you want a general purpose group, we can use whatever one you want, and just make the forge-discussion-owners group inherit the membership from the general purpose group.

Sounds like you don't really need a members group at all. lets just make the `forge-discussion-owners` map to the owners team. Then if you want to add access, you can add them to that group. we are keeping the "forge-" prefix for all the forge permissions groups, but if you want a general purpose group, we can use whatever one you want, and just make the forge-discussion-owners group inherit the membership from the general purpose group.
Author

As mentioned, we need a general group that is not only for forge. Let's finalize to use not the old FAS group but create a new one: Fedora-Discussion or Discussion (this is a SIG, not only related to the activities on Forge). I suggest to delete the old ask-fedora, as the name refers to a no-longer-existing Discourse instance.

As far as it concerns forge, the need would be that every owner/sponsor (the mentioned group of 8 people) of the FAS group / SIG becomes an owner of Forge. But the members of the FAS/SIG who are not owners/sponsors should not become owner access to Forge: one of the reasons we choose Docs/Forge is to avoid that every member of the SIG can re-write the official / published rules.

If we can manually add FAS accounts to Forge and give them any privileges (such as commit), and if I assume right that every Forge/FAS member at all can do tickets and PR, then you are right: we do not need a members group for forge in this case. We can do that manually. Then the forge-specific part would be Just a mapping from FAS Fedora-Discussion OWNER to forge-discussion-owner.

My expectation was that other SIG with FAS groups also not allow every member automatically full rights to make changes. So I assumed that possible?

new fas group: forge-discussion-owners sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm

+ jflory7 :)

As mentioned, we need a general group that is not only for forge. Let's finalize to use not the old FAS group but create a new one: `Fedora-Discussion` or `Discussion` (this is a SIG, not only related to the activities on Forge). I suggest to delete the old `ask-fedora`, as the name refers to a no-longer-existing Discourse instance. As far as it concerns forge, the need would be that every owner/sponsor (the mentioned group of 8 people) of the FAS group / SIG becomes an owner of Forge. But the members of the FAS/SIG who are not owners/sponsors should not become owner access to Forge: one of the reasons we choose Docs/Forge is to avoid that every member of the SIG can re-write the official / published rules. If we can manually add FAS accounts to Forge and give them any privileges (such as commit), and if I assume right that every Forge/FAS member at all can do tickets and PR, then you are right: we do not need a members group for forge in this case. We can do that manually. Then the forge-specific part would be Just a mapping from FAS `Fedora-Discussion` OWNER to `forge-discussion-owner`. My expectation was that other SIG with FAS groups also not allow every member automatically full rights to make changes. So I assumed that possible? > new fas group: forge-discussion-owners sponsors & owners @ankursinha , @alciregi , @jakfrost , @x3mboy , @kevin , @py0xc3 , @mattdm \+ jflory7 :)
Owner

This is now ready to go.

The https://accounts.fedoraproject.org/group/forge-discussion-owners/ group is now created, and the members are inherited from [discussion-mods](https://accounts.fedoraproject.org/group/discussion-mods) which has all the sponsors and owners listed above.

On next login, members of that group will be owners in the new forge org:

https://forge.fedoraproject.org/discussion

This is now ready to go. The https://accounts.fedoraproject.org/group/forge-discussion-owners/ group is now created, and the members are inherited from `[discussion-mods](https://accounts.fedoraproject.org/group/discussion-mods)` which has all the sponsors and owners listed above. On next login, members of that group will be owners in the new forge org: https://forge.fedoraproject.org/discussion
Author

@ryanlerch If we add members to discussion-mods that are not sponsors, they will not be mapped to forge-discussion-owners with any privilege that contains commit ?

@ryanlerch If we add members to `discussion-mods` that are **not** sponsors, they will **not** be mapped to `forge-discussion-owners` with any privilege that contains commit ?
Author

I have to re-open this ticket, we cannot leave it the way it is: now every "trust level"-based contributor of the SIG becomes owner of the Forge Discussion group and can delete repos. So that's more problematic than having a separated member group with committing privileges each.

If I understand it right how Forge and FAS are connected, I assume the only possibility is to create a third FAS group forge-discussion-members so that we have in total 3 FAS groups:

discussion-mods -> that's our FAS group of the SIG, for now, nothing more
forge-discussion-owners -> that's the owners of Forge who can create and delete repos and other actions that can cause serious issues. For now, it is likely to remain identical to the known 8 sponsors, though we might add "full moderators" or "site admins" to it on demand.
forge-discussion-members -> that's members of the Forge group with the least possible privileges (I assume that's commit privileges but not the right to delete/add repos, right?). We use this to involve some of the experienced TL4 members on demand in maintaining our guidelines or other stuff in the repos, but this should only contain privileges that are revertible (so that we at the worst have to revert a commit or so). There is no general profile for this (only minimal requirements candidates have to fulfill when we need some on demand temporarily or permanently), so the sponsors would add people of the SIG here on demand and at the discretion of the mod group manually.

The 8 sponsors should be the same in all 3 FAS groups, but adding anyone to any of the 3 groups should not automatically lead to them being added also to any other group: e.g., we have SIG members who should not automatically get commit rights (and therefore also not the right to delete repos), which excludes that all members of discussion-mods are automatically members of forge-discussion-members or forge-discussion-owners.

I hope that make sense? :-)

I have to re-open this ticket, we cannot leave it the way it is: now every "trust level"-based contributor of the SIG becomes owner of the Forge Discussion group and can delete repos. So that's more problematic than having a separated member group with committing privileges each. If I understand it right how Forge and FAS are connected, I assume the only possibility is to create a third FAS group `forge-discussion-members` so that we have in total 3 FAS groups: `discussion-mods` -> that's our FAS group of the SIG, for now, nothing more `forge-discussion-owners` -> that's the owners of Forge who can create and delete repos and other actions that can cause serious issues. For now, it is likely to remain identical to the known 8 sponsors, though we might add "full moderators" or "site admins" to it on demand. `forge-discussion-members` -> that's members of the Forge group with the least possible privileges (I assume that's commit privileges but not the right to delete/add repos, right?). We use this to involve some of the experienced TL4 members on demand in maintaining our guidelines or other stuff in the repos, but this should only contain privileges that are revertible (so that we at the worst have to revert a commit or so). There is no general profile for this (only minimal requirements candidates have to fulfill when we need some on demand temporarily or permanently), so the sponsors would add people of the SIG here on demand and at the discretion of the mod group manually. The 8 sponsors should be the same in all 3 FAS groups, but adding anyone to any of the 3 groups should not automatically lead to them being added also to any other group: e.g., we have SIG members who should not automatically get commit rights (and therefore also not the right to delete repos), which excludes that all members of `discussion-mods` are automatically members of `forge-discussion-members` or `forge-discussion-owners`. I hope that make sense? :-)
py0xc3 reopened this issue 2026-03-26 12:27:02 +00:00
Owner

So you don't want discussion-mods mapped to anything?

So you don't want discussion-mods mapped to anything?
Author

I don't like it, but I see no alternatives: originally, the requirement was that not every SIG member can directly commit. But the current result is that every SIG member is owner: every member can currently commit and delete repos (we tested that before Easter), which we cannot allow.

We need to be able to manually add individual members of the SIG to forge to allow them to commit as members but not delete repos (which excludes owners), whereas not all SIG members shall be able to commit. Every other SIG member should be able to create MR/PR, which I assume everyone can do anyway.

So the sponsors should be the same in all three FAS groups, and add to the respective group on demand whoever is needed there. Some are just SIG members without special privileges on Forge and can create MR/PR, some shall commit directly, some are owners.

So, unless I understood something wrong ...

So you don't want discussion-mods mapped to anything?

yes, for now. The SIG's FAS group (discussion-mods) is not just for forge but also other things.

I don't like it, but I see no alternatives: originally, the requirement was that not every SIG member can directly commit. But the current result is that every SIG member is owner: every member can currently commit and delete repos (we tested that before Easter), which we cannot allow. We need to be able to manually add individual members of the SIG to forge to allow them to commit as members but not delete repos (which excludes owners), whereas not all SIG members shall be able to commit. Every other SIG member should be able to create MR/PR, which I assume everyone can do anyway. So the sponsors should be the same in all three FAS groups, and add to the respective group on demand whoever is needed there. Some are just SIG members without special privileges on Forge and can create MR/PR, some shall commit directly, some are owners. So, unless I understood something wrong ... > So you don't want discussion-mods mapped to anything? yes, for now. The SIG's FAS group (discussion-mods) is not just for forge but also other things.
Owner

It appears that what you are after is very doable, easily -- i am just having issues determining what and who you want in each group.

Can you tell me:

  1. Who are to be the members and sponsors for the forge-discussion-owners group, which will map to the owners team on forge. These are the super users for your organization, and have access to everything. Owner permissions cannot be tweaked, they are hard coded in forgejo. Note too, that all sponsors can do on FAS groups is add members to that group.

  2. Who are the sponsors and members for forge-discussion-members which will map to the members team? All other teams, you can manage the permissions for what they can do you can remove commit access, and just give them ticket access. Note too we can add more teams and FAS groups. for finer grained permissions if you want just a team that has access to managing tickets.

it might be easier altogehter to meet up in real time to discuss this.

It appears that what you are after is very doable, easily -- i am just having issues determining what and who you want in each group. Can you tell me: 1. Who are to be the members and sponsors for the `forge-discussion-owners` group, which will map to the owners team on forge. These are the super users for your organization, and have access to everything. Owner permissions cannot be tweaked, they are hard coded in forgejo. Note too, that all sponsors can do on FAS groups is add members to that group. 2. Who are the sponsors and members for `forge-discussion-members` which will map to the members team? All other teams, you can manage the permissions for what they can do you can remove commit access, and just give them ticket access. Note too we can add more teams and FAS groups. for finer grained permissions if you want just a team that has access to managing tickets. it might be easier altogehter to meet up in real time to discuss this.
Author

I guess we have a time zone issue :) I am in Matrix available most of the time until around 20:00 UTC+2/CEST (maybe 20:30), in case that is realistic (feel free to ping me there with @py0xc3 in the room you opened)

  1. Who are to be the members and sponsors for the forge-discussion-owners group, which will map to the owners team on forge. These are the super users for your organization, and have access to everything. Owner permissions cannot be tweaked, they are hard coded in forgejo. Note too, that all sponsors can do on FAS groups is add members to that group.

The group mentioned above (owners and sponsors are the same): ankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7

So it's the same as the sponsors of discussion-mods

  1. Who are the sponsors and members for forge-discussion-members which will map to the members team? All other teams, you can manage the permissions for what they can do you can remove commit access, and just give them ticket access. Note too we can add more teams and FAS groups. for finer grained permissions if you want just a team that has access to managing tickets.

The sponsors are again the same.

For members, the issue starts: this cannot be mapped 1:1. Only some members of discussion-mods are to become members (= to become allowed commit access), but some other members of discussion-mods are NOT intended to become members. This will change over time and we need to be able to do this short notice (so, short notice decide to add someone in this group, temporarily or permanently). I therefore assumed its most useful to just add the sponsors there, and then the sponsors can manually add and remove team members to give and remove commit access.

If I get it right, we can also have teams that have fine grained access: all access of members, but without immediate commit access (so they need to do PR/MR and then a member/owner must accept it). That would be great: in this group, every member of discussion-mods can be a member too (I assume this will not override higher privileges of other groups).

Sorry for the special needs :) I try to be available in Matrix most of the time.

I guess we have a time zone issue :) I am in Matrix available most of the time until around 20:00 UTC+2/CEST (maybe 20:30), in case that is realistic (feel free to ping me there with @py0xc3 in the room you opened) > 1. Who are to be the members and sponsors for the forge-discussion-owners group, which will map to the owners team on forge. These are the super users for your organization, and have access to everything. Owner permissions cannot be tweaked, they are hard coded in forgejo. Note too, that all sponsors can do on FAS groups is add members to that group. The group mentioned above (owners and sponsors are the same): ankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7 So it's the same as the **sponsors** of `discussion-mods` > 2. Who are the sponsors and members for forge-discussion-members which will map to the members team? All other teams, you can manage the permissions for what they can do you can remove commit access, and just give them ticket access. Note too we can add more teams and FAS groups. for finer grained permissions if you want just a team that has access to managing tickets. The sponsors are again the same. For members, the issue starts: this cannot be mapped 1:1. **Only some** members of `discussion-mods` are to become members (= to become allowed commit access), but **some other** members of `discussion-mods` are NOT intended to become members. This will change over time and we need to be able to do this short notice (so, short notice decide to add someone in this group, temporarily or permanently). I therefore assumed its most useful to just add the sponsors there, and then the sponsors can manually add and remove team members to give and remove commit access. If I get it right, we can also have teams that have fine grained access: all access of members, but without immediate commit access (so they need to do PR/MR and then a member/owner must accept it). That would be great: in this group, **every** member of `discussion-mods` can be a member too (I assume this will not override higher privileges of other groups). Sorry for the special needs :) I try to be available in Matrix most of the time.
Owner

ok, it sounds just like you need what we are using as the common setup for SIGS:

  1. a Fedora Accounts group forge-discussion-owners. with sponsors and members being both ankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7 and maps to the Owners team on the forge org.
  2. a Fedora Accounts group forge-discussion-members that inherits its membership from discussion-mods -- this group will not have any sponsors, as you simply add members to discussion-mods and this group inherits the members. This group maps to the "Members" team on forge, which you then can set the permissions for to what ever you want.
ok, it sounds just like you need what we are using as the common setup for SIGS: 1. a Fedora Accounts group `forge-discussion-owners`. with sponsors and members being both `ankursinha , alciregi , jakfrost , x3mboy , kevin , py0xc3 , mattdm, jflory7` and maps to the Owners team on the forge org. 2. a Fedora Accounts group `forge-discussion-members` that inherits its membership from `discussion-mods` -- this group will not have any sponsors, as you simply add members to `discussion-mods` and this group inherits the members. This group maps to the "Members" team on forge, which you then can set the permissions for to what ever you want.
Author

Sounds good. Regarding 2. -> You mean forge-discussion-owners can determine within forge what privileges every member (of the forge member group) has (including remove commit privileges from them), and then every member of discussion-mods would (indirectly through forge-discussion-members) automatically be added to forge with these member privileges? Or can we also individualize / customize individual members? Just to be sure I understand the implications :)

Sounds good. Regarding 2. -> You mean `forge-discussion-owners` can determine within forge what privileges every member (of the forge _member_ group) has (including remove commit privileges from them), and then every member of `discussion-mods` would (indirectly through `forge-discussion-members`) automatically be added to forge with these _member_ privileges? Or can we also individualize / customize individual members? Just to be sure I understand the implications :)
Owner

@py0xc3 wrote in #449 (comment):

Sounds good. Regarding 2. -> You mean forge-discussion-owners can determine within forge what privileges every member (of the forge member group) has (including remove commit privileges from them), and then every member of discussion-mods would (indirectly through forge-discussion-members) automatically be added to forge with these member privileges? Or can we also individualize / customize individual members? Just to be sure I understand the implications :)

Every member of the forge-discussion-members group in FAS would be a member of the "Members" team in forge. and have the privs that you specify for that team (can be commit to all or specific repos, or just ticket privs to all or specific repos).

@py0xc3 wrote in https://forge.fedoraproject.org/forge/forge/issues/449#issuecomment-615327: > Sounds good. Regarding 2. -> You mean `forge-discussion-owners` can determine within forge what privileges every member (of the forge _member_ group) has (including remove commit privileges from them), and then every member of `discussion-mods` would (indirectly through `forge-discussion-members`) automatically be added to forge with these _member_ privileges? Or can we also individualize / customize individual members? Just to be sure I understand the implications :) Every member of the forge-discussion-members group in FAS would be a member of the "Members" team in forge. and have the privs that you specify for that team (can be commit to all or specific repos, or just ticket privs to all or specific repos).
Author

Looks good. Just checked in the security SIG how that works. Seems to fit.

Let's do it that way.

We maybe ask at some point in the future to get another member group, for us to add those who shall be able to commit to repos but without other ownership privileges, but we do not yet know for sure if that will be even necessary, so let's stick for now with the way you suggested. Thanks again!

Looks good. Just checked in the security SIG how that works. Seems to fit. Let's do it that way. We maybe ask at some point in the future to get another member group, for us to add those who shall be able to commit to repos but without other ownership privileges, but we do not yet know for sure if that will be even necessary, so let's stick for now with the way you suggested. Thanks again!
Owner

Permissions for the members team on forge is pretty low (read on repos), but this can be adjusted appropriately by an org owner.

* https://accounts.fedoraproject.org/group/forge-discussion-owners/ ** Sponsors: @ankursinha, @alciregi, @jakfrost, @x3mboy, @kevin, @py0xc3 , @mattdm, @jflory7 ** Members: : @ankursinha, @alciregi, @jakfrost, @x3mboy, @kevin, @py0xc3 , @mattdm, @jflory7 * https://accounts.fedoraproject.org/group/forge-discussion-members/ * Sponsors: None * Members: inherited from `https://accounts.fedoraproject.org/group/discussion-mods/` Permissions for the members team on forge is pretty low (read on repos), but this can be adjusted appropriately by an org owner.
Author

I assume it's intended that https://accounts.fedoraproject.org/group/forge-discussion-members/ leads to a 404 error. However, I have seen after my recent login that I was added additionally to the forge members group, so it seems to work. Thanks!

I assume it's intended that https://accounts.fedoraproject.org/group/forge-discussion-members/ leads to a 404 error. However, I have seen after my recent login that I was added additionally to the forge members group, so it seems to work. Thanks!
Sign in to join this conversation.
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
forge/forge#449
No description provided.