Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
8609572
feat(github): provision the enterprise owner role under github app auth
mateoHernandez123 Sep 22, 2026
04872b2
chore(github): extract the repeated GET literal in the endpoint mocks
mateoHernandez123 Sep 22, 2026
212f445
fix(github): bound the installations walk and reject traversal segments
mateoHernandez123 Sep 22, 2026
4203291
fix(github): keep the connector context for the memoized token refresher
mateoHernandez123 Sep 22, 2026
118b0b7
refactor(github): drop the traversal guard and state what escaping co…
mateoHernandez123 Sep 22, 2026
3ae0c2b
refactor(github): look up the enterprise installation directly instea…
mateoHernandez123 Sep 22, 2026
c9de9ce
fix(github): report an exhausted page budget as itself and log the sk…
mateoHernandez123 Sep 22, 2026
8301561
fix(github): retry an unclassified client build failure instead of re…
mateoHernandez123 Sep 22, 2026
445cff9
fix(github): skip an enterprise without an app installation instead o…
mateoHernandez123 Sep 23, 2026
32d2e00
fix(github): stand down enterprise roles on an ambiguous config and r…
mateoHernandez123 Sep 23, 2026
7c843cb
fix(github): fail the sync when no enterprise client can be built ins…
mateoHernandez123 Sep 23, 2026
fcd304a
feat(github): put enterprise owner provisioning behind an opt-in flag
mateoHernandez123 Sep 23, 2026
0c93921
refactor(github): memoize only a successful client build so a fixed c…
mateoHernandez123 Sep 23, 2026
764bdec
docs(github): document the enterprise owner provisioning flag where t…
mateoHernandez123 Sep 23, 2026
a5b1304
fix(github): give the page-limit errors a grpc code like the rest of …
mateoHernandez123 Sep 23, 2026
4e7fa1d
fix(github): advertise enterprise role provisioning only where it can…
mateoHernandez123 Sep 23, 2026
ec0f946
fix(github): stop registering the pat-only license type under app auth
mateoHernandez123 Sep 23, 2026
adc027c
fix(github): keep the license type registered until enterprise owners…
mateoHernandez123 Sep 23, 2026
5a033f5
test(github): lock provisioning to the deployments that can use it
mateoHernandez123 Sep 23, 2026
e28eb7b
docs(github): correct what the opt-in changes and drop the limitation…
mateoHernandez123 Sep 23, 2026
2a8e890
fix(github): address enterprise owner review findings
mateoHernandez123 Sep 24, 2026
8943329
docs(github): drop the last mention of the removed promote fallback
mateoHernandez123 Sep 24, 2026
f94e8a6
feat(github): publish the full capability set via a default capabilit…
mateoHernandez123 Sep 25, 2026
9858ffa
docs(github): document the enterprise owner provisioning setup
mateoHernandez123 Sep 25, 2026
7f940ca
docs(github): fix the enterprise install step order and list enterpri…
mateoHernandez123 Sep 25, 2026
b91d9b7
fix(github): let personal access token deployments configure enterpri…
mateoHernandez123 Sep 29, 2026
8b5a601
docs(github): say that enterprises without the opt-in fails the sync …
mateoHernandez123 Sep 29, 2026
414af6a
fix(github): fail the grant sync when the enterprise organization sto…
mateoHernandez123 Sep 29, 2026
d2e8251
fix(github): reject an owner grant for someone outside the enterprise
mateoHernandez123 Sep 30, 2026
fd2c62c
fix(github): page the membership search so a crowded login is still f…
mateoHernandez123 Sep 30, 2026
6fc083c
fix(github): drop the opt-in flag and key enterprise owners on the cr…
mateoHernandez123 Oct 1, 2026
65fe241
docs(github): drop the last references to the removed opt-in
mateoHernandez123 Oct 1, 2026
034425d
docs(github): state what the wrapper inherits on GHES now that the cr…
mateoHernandez123 Oct 1, 2026
df5c69f
fix(github): keep the enterprise surface out of this connector's conf…
mateoHernandez123 Oct 1, 2026
5484b12
docs(github): align the provisioner comments with registering on eith…
mateoHernandez123 Oct 1, 2026
c4a5d20
docs(github): give the enterprise permission block both credentials
mateoHernandez123 Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 0 additions & 51 deletions .github/workflows/capabilities_and_config.yaml

This file was deleted.

13 changes: 12 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,11 @@ baton resources
- Users
- Teams
- Repositories
- Organization roles
- Invitations (users invited to an organization who have not accepted yet)
- GitHub Apps (installed in organizations, synced as non-human identities)
- Enterprise roles, only when `--enterprises` is set. A personal access token syncs every role; a GitHub App syncs the built-in Enterprise Owner role and can also grant and revoke it, with the app installed on both the enterprise account and the organization
- Enterprise licenses, only when `--enterprises` is set and the connector authenticates with a personal access token. The API behind them is not available to GitHub Apps, so the type is not registered on the app path

By default, `baton-github` will sync information from any organizations that the provided credential has Administrator permissions on. You can specify exactly which organizations you would like to sync using the `--orgs` flag.

Expand Down Expand Up @@ -78,7 +82,7 @@ Flags:
--app-privatekey-path string Path to private key that is used to connect to the GitHub App. Ignored when app-privatekey is set. ($BATON_APP_PRIVATEKEY_PATH)
--client-id string The client ID used to authenticate with ConductorOne ($BATON_CLIENT_ID)
--client-secret string The client secret used to authenticate with ConductorOne ($BATON_CLIENT_SECRET)
--enterprises strings Sync enterprise roles, must be an admin of the enterprise. ($BATON_ENTERPRISES)
--enterprises strings Sync enterprise roles, must be an admin of the enterprise. A personal access token syncs every role. A GitHub App syncs and provisions the built-in Owner role instead, and needs to be installed on the enterprise account as well as on the organization, with the "Enterprise people: read and write" permission. ($BATON_ENTERPRISES)
--external-resource-c1z string The path to the c1z file to sync external baton resources with ($BATON_EXTERNAL_RESOURCE_C1Z)
--external-resource-entitlement-id-filter string The entitlement that external users, groups must have access to sync external baton resources ($BATON_EXTERNAL_RESOURCE_ENTITLEMENT_ID_FILTER)
-f, --file string The path to the c1z file to sync with ($BATON_FILE) (default "sync.c1z")
Expand Down Expand Up @@ -113,3 +117,10 @@ Org:
Repo:
- Administrator: Read and Write
- This permission implies Metadata: Read

Enterprise, only when `--enterprises` is set:
- GitHub App: People: Read and Write, and the app installed on the enterprise
account as well as the organization — required to sync and provision the
built-in Enterprise Owner role
- Personal access token: `read:enterprise` — required to sync enterprise roles
and licenses
70 changes: 69 additions & 1 deletion baton_capabilities.json
Original file line number Diff line number Diff line change
Expand Up @@ -55,6 +55,29 @@
]
}
},
{
"resourceType": {
"id": "enterprise_role",
"displayName": "Enterprise Role",
"traits": [
"TRAIT_ROLE"
],
"annotations": [
{
"@type": "type.googleapis.com/c1.connector.v2.V1Identifier",
"id": "enterprise_role"
},
{
"@type": "type.googleapis.com/c1.connector.v2.SkipEntitlements"
}
]
},
"capabilities": [
"CAPABILITY_SYNC",
"CAPABILITY_PROVISION"
],
"permissions": {}
},
{
"resourceType": {
"id": "invitation",
Expand All @@ -80,6 +103,32 @@
"permissions": {},
"skipSyncAnomalyDetection": true
},
{
"resourceType": {
"id": "license",
"displayName": "License",
"traits": [
"TRAIT_LICENSE_PROFILE"
],
"annotations": [
{
"@type": "type.googleapis.com/c1.connector.v2.V1Identifier",
"id": "license"
},
{
"@type": "type.googleapis.com/c1.connector.v2.SkipEntitlements"
},
{
"@type": "type.googleapis.com/c1.connector.v2.OptInRequired"
}
]
},
"capabilities": [
"CAPABILITY_SYNC"
],
"permissions": {},
"optInRequired": true
},
{
"resourceType": {
"id": "org",
Expand Down Expand Up @@ -166,6 +215,24 @@
],
"permissions": {}
},
{
"resourceType": {
"id": "usage-app",
"displayName": "GitHub Activity",
"traits": [
"TRAIT_APP"
],
"annotations": [
{
"@type": "type.googleapis.com/c1.connector.v2.SkipGrants"
}
]
},
"capabilities": [
"CAPABILITY_SYNC"
],
"permissions": {}
},
{
"resourceType": {
"id": "user",
Expand All @@ -191,7 +258,8 @@
"CAPABILITY_PROVISION",
"CAPABILITY_SYNC",
"CAPABILITY_ACCOUNT_PROVISIONING",
"CAPABILITY_RESOURCE_DELETE"
"CAPABILITY_RESOURCE_DELETE",
"CAPABILITY_EVENT_FEED_V2"
],
"credentialDetails": {
"capabilityAccountProvisioning": {
Expand Down
5 changes: 4 additions & 1 deletion cmd/baton-github/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -14,5 +14,8 @@ var version = "dev"

func main() {
ctx := context.Background()
config.RunConnector(ctx, "baton-github", version, cfg.Config, connector.NewLambdaConnector, connectorrunner.WithSessionStoreEnabled())
config.RunConnector(ctx, "baton-github", version, cfg.Config, connector.NewLambdaConnector,
connectorrunner.WithSessionStoreEnabled(),
connectorrunner.WithDefaultCapabilitiesConnectorBuilderV2(&connector.DefaultCapabilitiesBuilder{}),
)
}
2 changes: 1 addition & 1 deletion config_schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@
{
"name": "enterprises",
"displayName": "Enterprises",
"description": "Sync enterprise roles, must be an admin of the enterprise.",
"description": "Sync enterprise roles, must be an admin of the enterprise. A personal access token syncs every role. A GitHub App syncs and provisions the built-in Owner role instead, and needs to be installed on the enterprise account as well as on the organization, with the \"Enterprise people: read and write\" permission.",
"stringSliceField": {}
},
{
Expand Down
Loading
Loading