TL-M0-28 · GitHub Team: the ruleset, Claude's access and the board
Why: D28 puts Opleettop on GitHub Team. This step protects main on GitHub's side, turns on Dependabot alerts, creates the labels and the Opleet v2 board where work is tracked from now on, and gives the Claude GitHub app this repository and nothing else. The app takes no seat; only you do.
ID TL-M0-28 · Level L0 · Run order row 14b · Issue #9
main takes changes only through pull requests whose checks pass; Dependabot alerts are on; the labels and the Opleet v2 board exist; Claude can reach Opleettop/monorepo and no other repository.
Before
Section titled “Before”- Opleettop is on GitHub Team (D28). TL-M0-26 is Done.
- You are in the repository folder on main with nothing to commit, and gh auth status shows you logged in.
1 · Point this folder at Opleettop/monorepo and check its merge settings
Section titled “1 · Point this folder at Opleettop/monorepo and check its merge settings”git remote set-url origin https://github.com/Opleettop/monorepo.gitgit fetch --prune origingit status -sbgh repo view Opleettop/monorepo --json visibility,squashMergeAllowed,mergeCommitAllowed,rebaseMergeAllowed,deleteBranchOnMerge2 · The ruleset on main: a pull request with checks and pr-title green, squash merges only, no force push, no deletion
Section titled “2 · The ruleset on main: a pull request with checks and pr-title green, squash merges only, no force push, no deletion”gh api -X POST repos/Opleettop/monorepo/rulesets --input - <<'EOF'{ "name": "main", "target": "branch", "enforcement": "active", "conditions": { "ref_name": { "include": ["~DEFAULT_BRANCH"], "exclude": [] } }, "rules": [ { "type": "deletion" }, { "type": "non_fast_forward" }, { "type": "pull_request", "parameters": { "required_approving_review_count": 0, "dismiss_stale_reviews_on_push": false, "require_code_owner_review": false, "require_last_push_approval": false, "required_review_thread_resolution": false, "allowed_merge_methods": ["squash"] } }, { "type": "required_status_checks", "parameters": { "strict_required_status_checks_policy": false, "required_status_checks": [{ "context": "checks" }, { "context": "pr-title" }] } } ]}EOF3 · Try to push to main directly, past the local guard, then drop the test commit
Section titled “3 · Try to push to main directly, past the local guard, then drop the test commit”git commit --allow-empty -m "chore: test the ruleset"git push --no-verify origin maingit reset --hard origin/main4 · Dependabot alerts
Section titled “4 · Dependabot alerts”gh api -X PUT repos/Opleettop/monorepo/vulnerability-alerts5 · Labels: the kind of item, and the role that owns it
Section titled “5 · Labels: the kind of item, and the role that owns it”gh label create "type: task" --repo Opleettop/monorepo --color 1E6F5E --description "Work to do: a step, a pack or a fix"gh label create "type: question" --repo Opleettop/monorepo --color D48C17 --description "An open question; replaces the register's OQ table"gh label create "type: change request" --repo Opleettop/monorepo --color CF4440 --description "A decision or rule conflicts with what the work shows"gh label create "type: decision" --repo Opleettop/monorepo --color 2F7BCC --description "A proposed decision for zuki to accept"gh label create "role: cto" --repo Opleettop/monorepo --color 56665F --description "CTO session"gh label create "role: backend" --repo Opleettop/monorepo --color 56665F --description "Backend Engineer"gh label create "role: frontend" --repo Opleettop/monorepo --color 56665F --description "Frontend Engineer"gh label create "role: docs" --repo Opleettop/monorepo --color 56665F --description "Docs Engineer"gh label create "role: zuki" --repo Opleettop/monorepo --color 56665F --description "zuki: a run, a decision or a review"6 · The board: give gh the project scope once, create Opleet v2 with a Phase field, and link it to the repository
Section titled “6 · The board: give gh the project scope once, create Opleet v2 with a Phase field, and link it to the repository”gh auth refresh -h github.com -s projectgh project create --owner Opleettop --title "Opleet v2"gh project list --owner OpleettopBelow, <PROJECT_NUMBER> is the number the list shows for Opleet v2.
gh project field-create <PROJECT_NUMBER> --owner Opleettop --name Phase --data-type SINGLE_SELECT --single-select-options "M0,Data,M1,M2,M3,M4,M5,M6,M7,Cutover"gh project link <PROJECT_NUMBER> --owner Opleettop --repo monorepogh project view <PROJECT_NUMBER> --owner Opleettop --webIn the browser: Workflows › Auto-add to project › Edit: repository monorepo, filter is:issue,pr is:open, then save and turn it on. Check that Item closed and Pull request merged are on and set Status to Done.
7 · Give Claude this repository and nothing else
Section titled “7 · Give Claude this repository and nothing else”In claude.ai: Settings › Connectors › GitHub, connect or configure it. On the GitHub page that opens, install it on Opleettop, choose Only select repositories, pick monorepo and save.
open "https://github.com/organizations/Opleettop/settings/installations"In the browser: Claude's repository access shows monorepo only. Then tell the CTO session the app is in; it attaches the repository and opens the first pull request.
Expect
Section titled “Expect”- Block 1: git status shows “## main...origin/main” with nothing ahead or behind; the JSON shows PRIVATE, squashMergeAllowed true, mergeCommitAllowed false, rebaseMergeAllowed false and deleteBranchOnMerge true.
- Block 2: a JSON reply with "name": "main" and "enforcement": "active".
- Block 3: the push is refused with “GH013: Repository rule violations”.
- Block 4: prints nothing.
- Block 5: “✓ Label … created in Opleettop/monorepo”, nine times.
- Block 6: each command prints what it made, and the browser shows the Opleet v2 board.
- Block 7: the installations page lists monorepo under Claude.
gh api repos/Opleettop/monorepo/rules/branches/main --jq '.[].type'Lists deletion, non_fast_forward, pull_request and required_status_checks.
gh api repos/Opleettop/monorepo/vulnerability-alerts --silent && echo "alerts on"Prints “alerts on”.
gh label list --repo Opleettop/monorepoShows the nine labels next to GitHub's default ones.
If it fails
Section titled “If it fails”- Block 1: git fetch says Repository not found: gh and git aren't logged in as an owner of Opleettop. Paste what gh auth status prints into a CTO session.
- Block 1: git status shows [gone], because Opleettop/monorepo is empty: run git push --no-verify -u origin main once (the guard blocks pushes to main; this first push is the one exception), then blocks 2 and 3 of TL-M0-12 with Opleettop/monorepo in place of <GITHUB_OWNER>/opleet, then go on with block 2 here.
- Block 1: git status shows main and origin/main diverged, because the repository was created with a README or a licence: stop and paste what it prints into a CTO session.
- Block 1: the merge settings differ: run blocks 2 and 3 of TL-M0-12 with Opleettop/monorepo in place of <GITHUB_OWNER>/opleet.
- Block 2 answers 403 or Not Found: gh lacks admin rights here. Run gh auth refresh -h github.com -s repo,read:org, then block 2 again. Any other error: paste the reply into a CTO session.
- Block 3's push goes through: the ruleset isn't active. The test commit is empty; leave it, and check Settings › Rules › Rulesets › main.
- Block 6 says the token lacks the project scope: run the gh auth refresh line again and finish its browser step.
gh api repos/Opleettop/monorepo/rulesets --jq '.[] | select(.name == "main") | .id'gh api -X DELETE repos/Opleettop/monorepo/rulesets/<RULESET_ID>Labels: gh label delete "<label>" --repo Opleettop/monorepo --yes. The board: gh project delete <PROJECT_NUMBER> --owner Opleettop. Claude: remove monorepo from its repository access.
Log each run as a comment on #9.