ProdgatorDocs
GatesRelease policies

Allowed actors

A form rule that limits who may start a release or author a pull request, and can require an approval from someone else.

Availability

Works in release policies (Business plan and above) and pull request policies (Team plan and above). Approver groups in a pull request policy need the Business plan. Creating and changing policies needs the role.

The Allowed actors rule checks who is behind a change:

  • On a release, the actor of the deployment's GitHub Actions workflow run: the person (or bot) who triggered the run, or re-ran it.
  • On a pull request, its author.

Use it to let only your release managers start production releases, to keep bots or contractors from opening pull requests to a protected branch, or to make sure the author is never the only person who approved.

Settings

SettingMeaning
Allowed GitHub usersUp to 100 GitHub logins, matched exactly and without regard to case. A bot keeps its suffix, for example . Wildcards are not supported.
Allowed approver groupsApprover groups whose members are allowed.
Blocked GitHub usersLogins that fail the rule.
Blocked approver groupsGroups whose members fail the rule.
BotsTreat bots like other users (the default: a bot is allowed or blocked by its login), Allow every bot, or Block every bot.
Someone other than the author must approveThe rule waits until someone other than the actor approves.

Leave both allowed lists empty, and keep the bots setting off Allow every bot, to allow anyone who is not blocked. A rule needs at least one list entry, a bots setting other than the default, or the approver check.

How the rule decides

  1. If Prodgator does not know the actor, the rule returns . On a release, that happens when Prodgator could not read the workflow run from GitHub; it tries again later.
  2. A blocked user, a member of a blocked group, or any bot with Block every bot fails the rule. Blocked wins over allowed.
  3. With an allowed list, the actor must be one of the allowed users, a member of an allowed group, or a bot with Allow every bot. Anyone else fails the rule.
  4. With Someone other than the author must approve, the rule is pending until another person approves. Then it passes.

The reason names the actor and what decided, for example "octocat may not start this release: not on the allowed list" or "dependabot[bot] may not author this pull request: bots are blocked".

Approver groups need a linked account

Prodgator knows a person's approver groups only when they have linked their GitHub account in Prodgator. An actor without a linked account is in no group, so an allowed group cannot match them. The reason says so: "(no linked Prodgator account, so groups cannot match)". Allowed and blocked users match by login and work without a linked account.

GitHub teams

GitHub team membership is not part of the input, so the rule cannot match a GitHub team. Create an approver group with the same people instead.

Bots

A bot is a GitHub account of type , or any login ending in , such as , or . To allow one bot and no others, keep the default bots setting and add that bot's login to the allowed users.

The second approver

With Someone other than the author must approve, these approvals count:

  • an approval given in Prodgator by anyone other than the actor (matched by linked account or by GitHub login); on a pull request, only on the current commit,
  • on a pull request, an approving GitHub review of the latest commit by anyone other than the author.

Rejections and comments do not count. This check does not require the approver to be in a group: combine it with a Prodgator approvers rule, or a GitHub reviews rule on pull requests, when the approver must come from a list.

Template

Only release managers can release is a release policy with one blocking Allowed actors rule. Pick your release manager group on the customize step, then bind the policy to a gate such as Production. See Policy templates.

What the rule reads

The rule reads from the input document: , , , and . See the release input document and the pull request input document. Evaluations stored before and existed lack them; when such an input is replayed in the playground, groups match nobody and bots are recognised by their login suffix.

The rule's evidence lists the actor, whether they are linked, their groups, whether they are a bot, the reasons they were blocked and the people who counted as another approver.

On this page