Skip to content

About

Hourly sync that adds Gold Rush Robotics GitHub org members to the everyone team.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

GitHub Sync

Repository for all standalone GitHub webhook items for 49er robotics.

Currently the only thing this repo does is run an hourly task that adds everyone in our GitHub organization to a team.

The service uses PyGithub to add missing members. Existing team maintainers keep their roles. Organization owners are included; outside collaborators and unaccepted organization invitations are not. Membership lists are paginated, so organizations with more than 100 members are supported.

GitHub automatically removes departing organization members from teams, so the service only adds members and leaves removals to GitHub. See GitHub's organization membership API.

Production setup

Create the everyone team before starting the service.

In your organization's Settings → Developer settings → GitHub Apps, open (or create) your app:

  1. Set Permissions & events → Organization permissions → Members to Read and write. Disable webhooks; this service polls hourly.
  2. On the app's General page, copy its numeric App ID.
  3. Under Private keys, click Generate a private key. Save the downloaded .pem file.
  4. Click Install App and install it on your organization. If you changed permissions for an existing installation, approve those changes.

See GitHub's app registration instructions.

In this repository, create a directory for the downloaded key:

mkdir -p secrets
chmod 700 secrets
cp /path/to/downloaded-key.pem secrets/github-app.pem
chmod 644 secrets/github-app.pem

The directory restricts host access to your user. The file must be readable by Docker's non-root container user. Compose mounts it as a read-only secret; it is excluded from version control and the Docker image.

Edit .env to contain:

GITHUB_ORG=gold-rush-robotics
GITHUB_TEAM_SLUG=everyone
GITHUB_APP_ID=YOUR_NUMERIC_APP_ID
SYNC_INTERVAL_SECONDS=3600

Start production:

docker compose up -d --build --force-recreate
docker compose logs -f github-sync

It syncs immediately, then hourly.

Development

uv sync --locked
uv run ruff check .
uv run ruff format --check .

About

Hourly sync that adds Gold Rush Robotics GitHub org members to the everyone team.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages