Support parent (nested) teams - #83
Merged
Merged
Conversation
Add an optional `parent` (team name) to teams.yaml. The importer now captures the parent instead of rejecting nested teams, and teams.tf sets parent_team_id from the parent's slug (config lookup, not a github_team self-reference — that cycles across for_each instances). Verified end-to-end: apply nests the child on GitHub, no drift, import-org round-trips the parent. Follow-ups: validate parent references a defined team + no cycles; a brand-new parent has no slug yet, so hand-authoring a new parent+child needs the parent's slug (importer-owned) or a name->slug derivation.
The single-resource parent_team_id approaches either cycle (referencing github_team.team[parent].id across for_each instances) or race (config-string lookup gives no ordering, so a new parent+child in one apply can 404). Split into github_team.team (roots) and github_team.child_team (children referencing github_team.team[parent].id) — real dependency edge, no cycle, parent created before child. members.tf resolves team_id via a merged team_ids map. Existing teams are all roots, so no state address changes. Supports one level of nesting.
pavlovic-ivan
marked this pull request as ready for review
September 25, 2026 11:11
GET orgs/{org}/teams/{slug}/members returns members of child teams too
(flagged inherited=true), which go-github v67 drops. Decode it via a raw
request and skip inherited members, so a parent team is not recorded with
its children's members as direct members.
…atch The team import blocks split staged teams by the staged file's own parent, but the resources split by the merged map (final config wins). When a team's parent differs between staged and final (e.g. re-import after a parent change on GitHub), the import targeted a resource address that didn't exist: 'Configuration for import target does not exist'. Bucket staged teams by which merged bucket they're in instead.
dev-milos
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds optional
parent(team name) toorganisation/teams.yamlfor nested teams. The importer now captures the parent instead of rejecting nested teams.github_team.team(roots) /github_team.child_team(children referencinggithub_team.team[parent].id) — gives parent-before-child ordering without afor_eachself-cycle. Existing teams are all roots → no state-address change.Invalid index).docs/changing-team-nesting.md— child↔root transitions need aterraform state mvfirst (else destroy+recreate).Limitation: one level of nesting. G-Research org has 0 multi-level teams, so this matches real usage.
Draft — prototype validated end-to-end on the dev workspace (create ordering, import/adoption, reparent, lifecycle).