Skip to content

Commit 22b208e

Browse files
committed
docs: document release GitHub App permissions
Signed-off-by: Vitor Mattos <vitor@php.rio>
1 parent 62c65f8 commit 22b208e

1 file changed

Lines changed: 26 additions & 3 deletions

File tree

‎docs/release-automation.md‎

Lines changed: 26 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,12 +39,35 @@ Mutating stages use short-lived installation tokens.
3939

4040
External organizations must create and install their own GitHub App. Do not expect the LibreCode App to be installed in another organization. Follow the [GitHub App setup guide](https://github.com/LibreCodeCoop/release-tool/blob/main/docs/github-app.md) for the exact registration settings, repository permissions, installation scope, private-key generation, and Actions secret configuration.
4141

42+
The current shared actions require only these GitHub App **repository permissions**:
43+
44+
| Permission | Access |
45+
| --- | --- |
46+
| Contents | Read and write |
47+
| Pull requests | Read and write |
48+
49+
No organization permissions, account/user permissions, webhook subscriptions, Device Flow, or OAuth callback are required.
50+
51+
For a normal organization-internal installation:
52+
53+
1. create the App under **Organization → Settings → Developer settings → GitHub Apps**;
54+
2. choose **Only on this account**;
55+
3. disable webhooks and user authorization;
56+
4. configure only the two repository permissions above;
57+
5. generate a PEM private key;
58+
6. choose **Install App** and prefer **Only select repositories**;
59+
7. add the consumer repository;
60+
8. store the full PEM in **Repository/Organization → Settings → Secrets and variables → Actions**;
61+
9. pass the public App slug and that Actions secret to the release actions.
62+
63+
The complete walkthrough, including screenshots/navigation terminology, key rotation, organization-secret scoping, validation and troubleshooting, lives in the [GitHub App setup guide](https://github.com/LibreCodeCoop/release-tool/blob/main/docs/github-app.md).
64+
4265
The consumer passes:
4366

44-
- an App slug;
45-
- the App private key stored as an Actions secret.
67+
- the public App slug, for example `example-org-release-automation`;
68+
- the App private key stored as an Actions **secret**, not a variable.
4669

47-
The actions resolve the public client id from the slug and request only the permissions needed by each stage.
70+
The actions resolve the public client id from the slug and mint short-lived installation tokens scoped to the current repository and the permissions requested by that stage.
4871

4972
## Minimal workflow shape
5073

0 commit comments

Comments
 (0)