New organization: packaging #456
Labels
No labels
ai-review-please
Org/Team Modification
Private Issues
Runner Request
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
forge/forge#456
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Hello Fedora Infra Team,
I would like to request the creation of a new organization and associated
teams in Fedora Forge.
Desired Organization Name (Short Name): packager-tools
Full Name of Organization: Fedora Packager Tooling
Description of Organization's Purpose: This organization will host scripts, RPM macros, and other automation tooling for Fedora packaging.
Examples of projects that should live here:
I'm not sure how the teams structure should be set up. Each repository should have its own permissions structure. It should be possible for members of the
packagerFAS group to create repositories for packager tooling that are generally useful to Fedora packagers and don't fit under an established SIG in this organization. If Infra desires, a ticket-based process to create repositories can be used or maybe self-service can be offered toprovenpackagermembers only.@ryanlerch, what's the status of this?
Held off on this one, since the ticket over on the packaging committee was talking about what to name their repo, and were talking about some packaging tools there:
https://pagure.io/packaging-committee/issue/1527#comment-1008924
Since this is going to get messy, i think having two seperate orgs here is the way to go (Packaging Tools and Packaging Committee)
For this ticket, @gotmax23 how about this setup:
Owners team (full admin access) given to members of a new group
forge-packagingtools-ownerswhose group membership is inherited fromprovenpackagersMembers team (write access to tickets, read access to everything else, ability to create repos) is given to members of a new group
forge-packagingtools-memberswhose group membership is inherted frompackagers. If a user creates a repo, they are given admin access to that repo.All other commit access to repos is done by manually adding users as collaborators on a per-repo basis.
@ryanlerch and I discussed this on Matrix. I think the suggested setup is workable, there's just a question of whether forge-packagingtools-owners should contain all provenpackagers or just one or two people to serve as org admins.
I pointed out that it's an expansion of the role of provenpackagers that currently only applies to distgit permissions, but provenpackagers are already a trusted group, so perhaps it makes sense to give them access to packaging tools repos as well. Another option is to create a separate team in the packager-tools org that consists of provenpackagers so repo admins can choose to give all provenpackagers perms on a repo, but the team wouldn't automatically have global admins perms.
Okay, after a real-time chat with @gotmax23 in matrix, here is an ammended proposal:
Owners team (full admin access) given to members of a new group
forge-packagingtools-ownerswith sponsors and members list being: @gotmax23 + ???Provenpackagerforge team: given to members of a new groupforge-packagingtools-provenpackagerwith membership inhertied from the already existingprovenpackagerFAS group. Members of this team have write (or whatever) access to specific repos (a list that owners of the org or repos can update).Packagerforge team: given to members of a new groupforge-packagingtools-packagerwith membership inhertied from the already existingpackagerFAS group. Members of this team will have no specific access to repos in the org. But have the ability to create a new repo in the organization.Extra notes:
Hi @ryanlerch, I put a final proposal to handle this and #457 in https://pagure.io/packaging-committee/issue/1527. The FPC discussed this in the last meeting, and we prefer one
packagingorg over the two organization approach as long as we can properly handle permissions -- which I think we can. If the plan I wrote up in the Pagure issue looks good to you, can we move forward with it?New organization: packager-toolsto New organization: packagingFrom @gotmax23 on https://pagure.io/packaging-committee/issue/1527#comment-1011641
@ryanlerch wrote in #456 (comment):
This group and team have now been created, and are linked via mapping.
This group and team have now been created, and are linked via mapping.
I also set up the permissions for this one, so any repo that this team gets added to, they get Admin privs on -- org owners can change this in the team settings page.
This group and team have now been created, and are linked via mapping.
I also set up the permissions for this one, so any repo that this team gets added to, they only get read access to, but they have the "create new repos" flag turned on.
Added this to the org description. However org owners can tweak at any time.
Currently yes, but this default is turning out to be quite spammy for the way we have all our orgs set up in forge. So once i implement #529 later today, this should not be an issue anymore
You will need to change where the docs site build precess looks, e.g.
This group and team have now been created, and are linked via mapping.
I also set up the permissions for this one, so any repo that this team gets added to, they get write access.
This is not possible on the Forge side -- the OIDC login process that we use to populate the teams does not give us sponsors. However, this is likely be possible on the IPA side with some creative group inheritance. Will have to get further information on how the sponsors list is updated -- this is worth a seperate infra ticket i think, and i can explain my solution there if needs be.
No worries -- just file a ticket here at forge/forge and we will get it done.
Thanks for creating the org and answering all my questions. It looks like there is an issue with two of the groups/teams, though. I have been added to
which have a
fedora-prefix, not aforge-prefix like is configured in https://forge.fedoraproject.org/infra/ansible/src/commit/cea0a27b737837df664b83cdcbce0b52b2293bc0/roles/openshift-apps/forgejo/templates/values.yaml.j2#L564-L565. The Packager and Committee teams are currently empty, presumably because of the mismatched group names. Can either the group names in IPA or the Forgejo configuration be fixed?@gotmax23 wrote in #456 (comment):
Sorry about this, that was a error on my part.
I have created the proper groups now:
and have changed the ones i made in error to be empty:
We typically do not delete groups, but since these were made in error, and never actaully used, i will check with @kevin to see if they are ok to delete in this case.
gotmax23 referenced this issue from packaging/FedoraReview2026-06-29 17:26:52 +00:00