Skip to content

chore(sts): grant approver-doc-driven contents:write - #285

Draft
rawlingsj wants to merge 1 commit into
mainfrom
jamesrawlings/approver-doc-driven-automerge-perms
Draft

chore(sts): grant approver-doc-driven contents:write#285
rawlingsj wants to merge 1 commit into
mainfrom
jamesrawlings/approver-doc-driven-automerge-perms

Conversation

@rawlingsj

@rawlingsj rawlingsj commented Jul 31, 2026

Copy link
Copy Markdown
Member

Draft / do not merge until the subject is filled in.

The approver-doc-driven identity writes merge commits to the target repo's protected branch, so it needs contents: write (was read).

Two things gate merging this:

  1. contents: readwrite (this change).
  2. subject is still the placeholder 000…; it is seeded from the service account's uniqueId after the environment's first apply. That value must be filled in before merge, or the identity mints no tokens.

This identity writes merge commits to the target repo's protected branch, so it
needs contents:write rather than read.

The subject is still the placeholder; it is seeded from the service account's
uniqueId after the environment's first apply. Do not merge until that value is
filled in.
@rawlingsj
rawlingsj force-pushed the jamesrawlings/approver-doc-driven-automerge-perms branch from e0563d0 to 7729c0b Compare July 31, 2026 15:22
@rawlingsj rawlingsj changed the title chore(sts): approver-doc-driven needs contents:write to auto-merge chore(sts): grant approver-doc-driven contents:write Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant