Skip to content

ci: trust datadog-api-spec ci-cd via Octo STS - #4030

Merged
nogates merged 4 commits into
masterfrom
nogates/dd-octo-sts-datadog-api-spec
Sep 17, 2026
Merged

nogates merged 4 commits into
masterfrom
nogates/dd-octo-sts-datadog-api-spec

Conversation

@nogates

@nogates nogates commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Adds the repository-scoped dd-octo-sts policies required only by .github/workflows/ci-cd.yml.

  • the normal policy ID trusts the current source DataDog/datadog-api-spec
  • the matching .ddoghq policy ID trusts the post-migration source ddoghq/datadog-api-spec
  • any policy already used by the current workflow is preserved unchanged

The workflow selects the matching policy from github.repository_owner, so the same workflow works before and after the repository transfer.

@nogates
nogates requested review from a team as code owners September 17, 2026 10:09
@nogates nogates changed the title ci: trust datadog-api-spec workflows via Octo STS ci: trust datadog-api-spec ci-cd via Octo STS Sep 17, 2026
@nogates
nogates merged commit fd54699 into master Sep 17, 2026
15 checks passed
@nogates
nogates deleted the nogates/dd-octo-sts-datadog-api-spec branch September 17, 2026 12:21
github-actions Bot pushed a commit that referenced this pull request Sep 17, 2026
* ci: trust datadog-api-spec workflows via Octo STS

* ci: constrain token policies to master PRs

* ci: limit token policies to ci-cd

* ci: support current and post-migration sources fd54699
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants