Entitlements plugin for a robust audit log
Перейти к файлу
Grant Birkinbine 65a53dfe8a
Merge pull request #21 from github/updates
General Updates
2024-03-28 10:39:15 -06:00
.github add dependabot config 2024-03-28 09:31:28 -06:00
bin entitlements-gitrepo-auditor-plugin 2022-06-07 12:12:28 -04:00
lib bump entitlements-app and version 2024-03-27 14:16:51 -06:00
script modernize script/test and script/bootstrap and also update ci workflows to match 2024-03-27 14:24:11 -06:00
spec upgrade to ruby `3.3.0` 2024-03-27 14:29:57 -06:00
vendor/cache bump entitlements-app and version 2024-03-27 14:16:51 -06:00
.gitignore entitlements-gitrepo-auditor-plugin 2022-06-07 12:12:28 -04:00
.rubocop.yml upgrade to ruby `3.3.0` 2024-03-27 14:29:57 -06:00
.ruby-version upgrade to ruby `3.3.0` 2024-03-27 14:29:57 -06:00
Gemfile entitlements-gitrepo-auditor-plugin 2022-06-07 12:12:28 -04:00
Gemfile.lock bump entitlements-app and version 2024-03-27 14:16:51 -06:00
LICENSE add license 2022-06-07 10:31:33 -06:00
README.md docs fixes 2023-08-29 13:44:41 -06:00
entitlements-gitrepo-auditor-plugin.gemspec update development gems 2024-03-27 14:14:32 -06:00

README.md

entitlements-gitrepo-auditor-plugin

acceptance test lint build release codeql coverage style

entitlements-gitrepo-auditor-plugin is an entitlements-app plugin allowing further auditing capabilities in entitlements by writing each deploy log to a separate GitHub repo.

Usage

Your entitlements-app config config/entitlements.yaml runs through ERB interpretation automatically. You can extend your entitlements configuration to load plugins like so:

<%-
  unless ENV['CI_MODE']
    begin
      require_relative "/data/entitlements/lib/entitlements-and-plugins"
    rescue Exception
      begin
        require_relative "lib/entitlements-and-plugins"
      rescue Exception
        # We might not have the plugins installed and still want this file to be
        # loaded. Don't raise anything but silently fail.
      end
    end
  end
-%>

You can then define lib/entitlements-and-plugins like so:

#!/usr/bin/env ruby
# frozen_string_literal: true

ENV["BUNDLE_GEMFILE"] = File.expand_path("../../Gemfile", File.dirname(__FILE__))
require "bundler/setup"
require "entitlements"

# require entitlements plugins here
require "entitlements/auditor/gitrepo"
require "entitlements/util/gitrepo"

Any plugins defined in lib/entitlements-and-plugins will be loaded and used at entitlements-app runtime.

Features

Git Repo Auditing

You can add automatic auditing to a separate GitRepo by enabling the following entitlements.yaml config:

<%-
    # NOTE: GITREPO_SSH_KEY must be base64 encoded.
    sshkey = ENV.fetch("GITREPO_SSH_KEY")
    shipper = ENV.fetch("GIT_SHIPPER", "<unknown person>")
    what = ["entitlements", ENV.fetch("GIT_BRANCH", "<unknown branch>")].join("/")
    sha = ENV.fetch("GIT_SHA1", "<unknown sha>")
    url = "https://github.com/github/entitlements-config/commit/#{sha}"
    commit_message = "#{shipper} deployed #{what} (#{url})"
-%>
auditors:
  - auditor_class: GitRepo
    checkout_directory: <%= ENV["GITREPO_CHECKOUT_DIRECTORY"] %>
    commit_message: <%= commit_message %>
    git_name: GitRepoUser
    git_email: gitrepousers@users.noreply
    person_dn_format: uid=%KEY%,ou=People,dc=github,dc=net
    repo: github/entitlements-config-auditlog
    sshkey: '<%= sshkey %>'
<%- end -%>

At the end of each entitlements-app run, the entitlements-gitrepo-auditor-plugin will write a commit to the repo defined above with the details of the deployment.

Release 🚀

To release a new version of this Gem, do the following:

  1. Update the version number in the lib/version.rb file
  2. Run bundle install to update the Gemfile.lock file with the new version
  3. Commit your changes, push them to GitHub, and open a PR

Once your PR is approved and the changes are merged, a new release will be created automatically by the release.yml workflow. The latest version of the Gem will be published to the GitHub Package Registry and RubyGems.