Linked provider accounts
Link your own GitHub, GitLab, Bitbucket or Azure DevOps account so Prodgator can approve deployments and run stages as you, and see the accounts added from your sign-in or found by your email.
Availability
Some provider actions must be made by a person, not by Prodgator's organization-wide connection. GitHub records whoever submits a required-reviewer review as the reviewer, and GitLab records the approver of a protected environment deployment the same way. For those, Prodgator acts with your own provider account.
To link one:
- Open your profile (user menu, then Profile) and go to Linked accounts.
- Click Link GitHub, Link GitLab, Link Bitbucket or Link Azure DevOps, and approve the sign-in on the provider.
Once linked:
- You can approve GitHub required-reviewer gates and GitLab protected environment deployments from Prodgator, if the provider lists you as an eligible reviewer.
- Approval comments Prodgator posts name your provider account.
A provider account can be linked to one person per organization. If a link stops working (for example you revoked access on the provider), it shows Needs relinking; click Link GitHub again (or the matching provider). Unlink deletes Prodgator's token for that account; after that, make required-reviewer approvals on the provider.
Accounts added from sign-in
If you sign in to Prodgator with GitHub, GitLab or Microsoft, Prodgator adds that account to Linked accounts the first time you open the app after signing in, marked From sign-in. It is used only to recognize you:
- Activity, approvals and policy checks that come from the provider (for example a GitHub review or a GitLab approval) are attributed to you.
- Prodgator gets no token from your sign-in, so it cannot act as you with this account. To approve GitHub required-reviewer gates or GitLab protected environment deployments from Prodgator, click Link GitHub to approve as you (or GitLab) and approve the sign-in on the provider. The account then shows as a normal linked account.
Microsoft accounts are shown with the email you signed in with. They are not used for Azure DevOps: to be named on Azure DevOps approvals and runs, link your Azure DevOps account as described below. Google and Apple sign-ins add nothing.
A few rules:
- If another member of the organization already linked the same provider account, it stays with them and is not added to your profile.
- An account you linked yourself is never replaced by your sign-in account.
- If you unlink an account that came from sign-in, it is not added again when you next sign in. You can still link it yourself.
- Prodgator checks your sign-in accounts once per session, not on every page.
Accounts found by your email
Prodgator can find your GitHub or Azure DevOps account from your email address, so you do not have to link it yourself to be named on reviews and approvals. It only does this when both sides have checked the address:
- your Prodgator sign-in email is verified, and
- the provider has tied the same address to one account: it is on a domain your GitHub organization verified, or (for Azure DevOps organizations that use personal Microsoft accounts) it is the account's Microsoft sign-in name.
The email in a commit is never used on its own. Anyone can type any address into their git settings.
Linked for you: GitHub verified domain emails
When the address is on a domain your GitHub organization verified, Prodgator links the account the next time you sign in, without asking. GitHub has checked both the domain and your address, and Prodgator reads them through your organization's own GitHub connection. If GitHub last listed the address on that account more than 14 days ago, Prodgator asks you instead, as below.
You get a notification, and the account shows Linked automatically under Linked accounts. Its reviews and approvals count as yours from then on. If it is not your account, click Not mine, unlink: one click, no confirmation. Prodgator then never links or suggests that account to you again. You can still link it yourself.
Suggested to you: everything else
For any other match (for example the Azure DevOps sign-in name), you get a notification and Linked accounts asks Is it yours?:
- Yes, link it checks everything again and links the account, marked Found by email. From then on its reviews and approvals count as yours, as for an account added from sign-in. Prodgator gets no token this way, so to approve as you on the provider, click Link GitHub to approve as you (or the matching provider).
- Not me drops it. Prodgator does not suggest that account to you again.
A suggestion changes nothing until you answer. These rules apply to both:
- An account you already linked, or one added from sign-in, is never replaced.
- An account another member already linked stays with them.
- If you unlink an account, Prodgator does not link or suggest it to you again. You can still link it yourself.
- If two members have the same verified email, or one address belongs to two provider accounts, nothing is linked and nobody is asked. Admins see these under Admin Console > Identity > Accounts not linked by email, and the person the account belongs to can link it from their profile.
- GitLab gives Prodgator no verified emails, so GitLab accounts are still added from sign-in or linked by hand.
Prodgator stores only a keyed hash of each email for this, made with a key that belongs to your organization, never the address itself.
Link prompt
If your organization is connected to GitHub or GitLab and you have no linked account there that can approve as you, Prodgator shows a Link your GitHub account (or GitLab) prompt at the top of the page. One click starts the link. Not now hides it for that organization and provider in this browser. Readers do not see it, since they cannot approve.
Bitbucket
Linking a Bitbucket account is possible. Bitbucket approvals do not need it: they answer the Prodgator gate the deployment step waits on, and nothing is sent to Bitbucket as you. See Approve deployments.
Azure DevOps
Link your Azure DevOps account with Link Azure DevOps, which signs you in with Microsoft. Prodgator asks for your profile and permission to run builds, and no more. Prodgator then:
- shows your name on Azure Pipelines approvals and runs where Azure DevOps names you, so people see who is meant;
- cancels runs, re-runs failed jobs and rolls back as you, so Azure DevOps records you as the person who did it. Without a linked account, these actions ask you to link one first.
Linking does not let Prodgator approve an Azure DevOps native approval for you. You approve those in Azure DevOps. Prodgator's own gate does not need a linked account. See Approve deployments.