Skip to content

Support parent (nested) teams - #83

Merged
pavlovic-ivan merged 6 commits into
mainfrom
team-parent-support
Sep 25, 2026
Merged

pavlovic-ivan merged 6 commits into
mainfrom
team-parent-support

Conversation

@pavlovic-ivan

Copy link
Copy Markdown
Contributor

Adds optional parent (team name) to organisation/teams.yaml for nested teams. The importer now captures the parent instead of rejecting nested teams.

  • Split github_team.team (roots) / github_team.child_team (children referencing github_team.team[parent].id) — gives parent-before-child ordering without a for_each self-cycle. Existing teams are all roots → no state-address change.
  • validate-org rejects an undefined parent, multi-level nesting, and self-parent (clear message instead of Terraform's Invalid index).
  • Runbook docs/changing-team-nesting.md — child↔root transitions need a terraform state mv first (else destroy+recreate).

Limitation: one level of nesting. G-Research org has 0 multi-level teams, so this matches real usage.

Draft — prototype validated end-to-end on the dev workspace (create ordering, import/adoption, reparent, lifecycle).

Add an optional `parent` (team name) to teams.yaml. The importer now captures
the parent instead of rejecting nested teams, and teams.tf sets
parent_team_id from the parent's slug (config lookup, not a github_team
self-reference — that cycles across for_each instances).

Verified end-to-end: apply nests the child on GitHub, no drift, import-org
round-trips the parent.

Follow-ups: validate parent references a defined team + no cycles; a brand-new
parent has no slug yet, so hand-authoring a new parent+child needs the parent's
slug (importer-owned) or a name->slug derivation.
The single-resource parent_team_id approaches either cycle (referencing
github_team.team[parent].id across for_each instances) or race (config-string
lookup gives no ordering, so a new parent+child in one apply can 404).

Split into github_team.team (roots) and github_team.child_team (children
referencing github_team.team[parent].id) — real dependency edge, no cycle,
parent created before child. members.tf resolves team_id via a merged
team_ids map. Existing teams are all roots, so no state address changes.
Supports one level of nesting.
@pavlovic-ivan
pavlovic-ivan marked this pull request as ready for review September 25, 2026 11:11
GET orgs/{org}/teams/{slug}/members returns members of child teams too
(flagged inherited=true), which go-github v67 drops. Decode it via a raw
request and skip inherited members, so a parent team is not recorded with
its children's members as direct members.
…atch

The team import blocks split staged teams by the staged file's own parent, but
the resources split by the merged map (final config wins). When a team's parent
differs between staged and final (e.g. re-import after a parent change on
GitHub), the import targeted a resource address that didn't exist:
'Configuration for import target does not exist'. Bucket staged teams by which
merged bucket they're in instead.
@pavlovic-ivan
pavlovic-ivan merged commit 997fa76 into main Sep 25, 2026
1 check passed
@pavlovic-ivan
pavlovic-ivan deleted the team-parent-support branch September 25, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants