Allowed actors
A form rule that limits who may start a release or author a pull request, and can require an approval from someone else.
Availability
The Allowed actors rule checks who is behind a change:
- On a release, the actor of the deployment's GitHub Actions workflow run: the person (or bot) who triggered the run, or re-ran it.
- On a pull request, its author.
Use it to let only your release managers start production releases, to keep bots or contractors from opening pull requests to a protected branch, or to make sure the author is never the only person who approved.
Settings
| Setting | Meaning |
|---|---|
| Allowed GitHub users | Up to 100 GitHub logins, matched exactly and without regard to case. A bot keeps its suffix, for example . Wildcards are not supported. |
| Allowed approver groups | Approver groups whose members are allowed. |
| Blocked GitHub users | Logins that fail the rule. |
| Blocked approver groups | Groups whose members fail the rule. |
| Bots | Treat bots like other users (the default: a bot is allowed or blocked by its login), Allow every bot, or Block every bot. |
| Someone other than the author must approve | The rule waits until someone other than the actor approves. |
Leave both allowed lists empty, and keep the bots setting off Allow every bot, to allow anyone who is not blocked. A rule needs at least one list entry, a bots setting other than the default, or the approver check.
How the rule decides
- If Prodgator does not know the actor, the rule returns . On a release, that happens when Prodgator could not read the workflow run from GitHub; it tries again later.
- A blocked user, a member of a blocked group, or any bot with Block every bot fails the rule. Blocked wins over allowed.
- With an allowed list, the actor must be one of the allowed users, a member of an allowed group, or a bot with Allow every bot. Anyone else fails the rule.
- With Someone other than the author must approve, the rule is pending until another person approves. Then it passes.
The reason names the actor and what decided, for example "octocat may not start this release: not on the allowed list" or "dependabot[bot] may not author this pull request: bots are blocked".
Approver groups need a linked account
Prodgator knows a person's approver groups only when they have linked their GitHub account in Prodgator. An actor without a linked account is in no group, so an allowed group cannot match them. The reason says so: "(no linked Prodgator account, so groups cannot match)". Allowed and blocked users match by login and work without a linked account.
GitHub teams
GitHub team membership is not part of the input, so the rule cannot match a GitHub team. Create an approver group with the same people instead.
Bots
A bot is a GitHub account of type , or any login ending in , such as , or . To allow one bot and no others, keep the default bots setting and add that bot's login to the allowed users.
The second approver
With Someone other than the author must approve, these approvals count:
- an approval given in Prodgator by anyone other than the actor (matched by linked account or by GitHub login); on a pull request, only on the current commit,
- on a pull request, an approving GitHub review of the latest commit by anyone other than the author.
Rejections and comments do not count. This check does not require the approver to be in a group: combine it with a Prodgator approvers rule, or a GitHub reviews rule on pull requests, when the approver must come from a list.
Template
Only release managers can release is a release policy with one blocking Allowed actors rule. Pick your release manager group on the customize step, then bind the policy to a gate such as Production. See Policy templates.
What the rule reads
The rule reads from the input document: , , , and . See the release input document and the pull request input document. Evaluations stored before and existed lack them; when such an input is replayed in the playground, groups match nobody and bots are recognised by their login suffix.
The rule's evidence lists the actor, whether they are linked, their groups, whether they are a bot, the reasons they were blocked and the people who counted as another approver.
Form rules
Rules you set up in a form, without Rego: Prodgator approvers, GitHub facts, attestations, required checks, change size, required reusable workflows, allowed actors and AI-assisted changes.
AI-assisted changes
A form rule that asks more of AI-assisted pull requests and releases: extra approvals, an approval from an approver group, or a label.