Skip to content

TL-M0-28 · GitHub Team: the ruleset, Claude's access and the board

Why: D28 puts Opleettop on GitHub Team. This step protects main on GitHub's side, turns on Dependabot alerts, creates the labels and the Opleet v2 board where work is tracked from now on, and gives the Claude GitHub app this repository and nothing else. The app takes no seat; only you do.

ID TL-M0-28 · Level L0 · Run order row 14b · Issue #9

main takes changes only through pull requests whose checks pass; Dependabot alerts are on; the labels and the Opleet v2 board exist; Claude can reach Opleettop/monorepo and no other repository.

  • Opleettop is on GitHub Team (D28). TL-M0-26 is Done.
  • You are in the repository folder on main with nothing to commit, and gh auth status shows you logged in.

1 · Point this folder at Opleettop/monorepo and check its merge settings

Section titled “1 · Point this folder at Opleettop/monorepo and check its merge settings”
Terminal window
git remote set-url origin https://github.com/Opleettop/monorepo.git
git fetch --prune origin
git status -sb
gh repo view Opleettop/monorepo --json visibility,squashMergeAllowed,mergeCommitAllowed,rebaseMergeAllowed,deleteBranchOnMerge

2 · The ruleset on main: a pull request with checks and pr-title green, squash merges only, no force push, no deletion

Section titled “2 · The ruleset on main: a pull request with checks and pr-title green, squash merges only, no force push, no deletion”
Terminal window
gh api -X POST repos/Opleettop/monorepo/rulesets --input - <<'EOF'
{
"name": "main",
"target": "branch",
"enforcement": "active",
"conditions": { "ref_name": { "include": ["~DEFAULT_BRANCH"], "exclude": [] } },
"rules": [
{ "type": "deletion" },
{ "type": "non_fast_forward" },
{
"type": "pull_request",
"parameters": {
"required_approving_review_count": 0,
"dismiss_stale_reviews_on_push": false,
"require_code_owner_review": false,
"require_last_push_approval": false,
"required_review_thread_resolution": false,
"allowed_merge_methods": ["squash"]
}
},
{
"type": "required_status_checks",
"parameters": {
"strict_required_status_checks_policy": false,
"required_status_checks": [{ "context": "checks" }, { "context": "pr-title" }]
}
}
]
}
EOF

3 · Try to push to main directly, past the local guard, then drop the test commit

Section titled “3 · Try to push to main directly, past the local guard, then drop the test commit”
Terminal window
git commit --allow-empty -m "chore: test the ruleset"
git push --no-verify origin main
git reset --hard origin/main
Terminal window
gh api -X PUT repos/Opleettop/monorepo/vulnerability-alerts

5 · Labels: the kind of item, and the role that owns it

Section titled “5 · Labels: the kind of item, and the role that owns it”
Terminal window
gh label create "type: task" --repo Opleettop/monorepo --color 1E6F5E --description "Work to do: a step, a pack or a fix"
gh label create "type: question" --repo Opleettop/monorepo --color D48C17 --description "An open question; replaces the register's OQ table"
gh label create "type: change request" --repo Opleettop/monorepo --color CF4440 --description "A decision or rule conflicts with what the work shows"
gh label create "type: decision" --repo Opleettop/monorepo --color 2F7BCC --description "A proposed decision for zuki to accept"
gh label create "role: cto" --repo Opleettop/monorepo --color 56665F --description "CTO session"
gh label create "role: backend" --repo Opleettop/monorepo --color 56665F --description "Backend Engineer"
gh label create "role: frontend" --repo Opleettop/monorepo --color 56665F --description "Frontend Engineer"
gh label create "role: docs" --repo Opleettop/monorepo --color 56665F --description "Docs Engineer"
gh label create "role: zuki" --repo Opleettop/monorepo --color 56665F --description "zuki: a run, a decision or a review"
Section titled “6 · The board: give gh the project scope once, create Opleet v2 with a Phase field, and link it to the repository”
Terminal window
gh auth refresh -h github.com -s project
gh project create --owner Opleettop --title "Opleet v2"
gh project list --owner Opleettop

Below, <PROJECT_NUMBER> is the number the list shows for Opleet v2.

Terminal window
gh project field-create <PROJECT_NUMBER> --owner Opleettop --name Phase --data-type SINGLE_SELECT --single-select-options "M0,Data,M1,M2,M3,M4,M5,M6,M7,Cutover"
gh project link <PROJECT_NUMBER> --owner Opleettop --repo monorepo
gh project view <PROJECT_NUMBER> --owner Opleettop --web

In the browser: Workflows › Auto-add to project › Edit: repository monorepo, filter is:issue,pr is:open, then save and turn it on. Check that Item closed and Pull request merged are on and set Status to Done.

7 · Give Claude this repository and nothing else

Section titled “7 · Give Claude this repository and nothing else”

In claude.ai: Settings › Connectors › GitHub, connect or configure it. On the GitHub page that opens, install it on Opleettop, choose Only select repositories, pick monorepo and save.

Terminal window
open "https://github.com/organizations/Opleettop/settings/installations"

In the browser: Claude's repository access shows monorepo only. Then tell the CTO session the app is in; it attaches the repository and opens the first pull request.

  • Block 1: git status shows “## main...origin/main” with nothing ahead or behind; the JSON shows PRIVATE, squashMergeAllowed true, mergeCommitAllowed false, rebaseMergeAllowed false and deleteBranchOnMerge true.
  • Block 2: a JSON reply with "name": "main" and "enforcement": "active".
  • Block 3: the push is refused with “GH013: Repository rule violations”.
  • Block 4: prints nothing.
  • Block 5: “✓ Label … created in Opleettop/monorepo”, nine times.
  • Block 6: each command prints what it made, and the browser shows the Opleet v2 board.
  • Block 7: the installations page lists monorepo under Claude.
Terminal window
gh api repos/Opleettop/monorepo/rules/branches/main --jq '.[].type'

Lists deletion, non_fast_forward, pull_request and required_status_checks.

Terminal window
gh api repos/Opleettop/monorepo/vulnerability-alerts --silent && echo "alerts on"

Prints “alerts on”.

Terminal window
gh label list --repo Opleettop/monorepo

Shows the nine labels next to GitHub's default ones.

  • Block 1: git fetch says Repository not found: gh and git aren't logged in as an owner of Opleettop. Paste what gh auth status prints into a CTO session.
  • Block 1: git status shows [gone], because Opleettop/monorepo is empty: run git push --no-verify -u origin main once (the guard blocks pushes to main; this first push is the one exception), then blocks 2 and 3 of TL-M0-12 with Opleettop/monorepo in place of <GITHUB_OWNER>/opleet, then go on with block 2 here.
  • Block 1: git status shows main and origin/main diverged, because the repository was created with a README or a licence: stop and paste what it prints into a CTO session.
  • Block 1: the merge settings differ: run blocks 2 and 3 of TL-M0-12 with Opleettop/monorepo in place of <GITHUB_OWNER>/opleet.
  • Block 2 answers 403 or Not Found: gh lacks admin rights here. Run gh auth refresh -h github.com -s repo,read:org, then block 2 again. Any other error: paste the reply into a CTO session.
  • Block 3's push goes through: the ruleset isn't active. The test commit is empty; leave it, and check Settings › Rules › Rulesets › main.
  • Block 6 says the token lacks the project scope: run the gh auth refresh line again and finish its browser step.
Terminal window
gh api repos/Opleettop/monorepo/rulesets --jq '.[] | select(.name == "main") | .id'
gh api -X DELETE repos/Opleettop/monorepo/rulesets/<RULESET_ID>

Labels: gh label delete "<label>" --repo Opleettop/monorepo --yes. The board: gh project delete <PROJECT_NUMBER> --owner Opleettop. Claude: remove monorepo from its repository access.

Log each run as a comment on #9.