Commit 3932e5f
authored
fix: import Twilio Dependabot files
## Summary
Import the two Dependabot files that [`tfroot-twilio` PR
#1](makeitworkcloud/tfroot-twilio#1) seeded
through the required pull-request path. This lets their canonical
`tfroot-github` resources adopt existing files instead of attempting
protected direct creation.
The import reports inherited commit metadata and a create-only setting
that would otherwise cause a protected-branch file update. The two
resource definitions therefore ignore only `commit_message` and
`overwrite_on_create`; their centrally managed file content remains
enforced.
Fixes # N/A — repair the failed central Dependabot adoption path.
## Type of change
- [x] Bug fix
- [ ] Feature / enhancement
- [ ] Documentation
- [x] Infrastructure (OpenTofu root or module)
- [ ] GitOps desired state (manifests, kustomize, charts, SOPS/KSOPS
secrets)
- [ ] Container image
- [ ] CI / reusable workflow
- [ ] Refactor / cleanup
- [ ] Breaking change
## Validation
- [x] Required pull-request checks pass — OpenTofu test and plan
succeeded in [run
33819976668](https://github.com/makeitworkcloud/tfroot-github/actions/runs/33819976668).
- [x] Plan is exactly `2 to import, 0 to add, 0 to change, 0 to
destroy`.
- [x] Generated or centrally distributed files were regenerated by their
owning automation, not hand-edited — the files were exact PR seeds and
retain `tfroot-github` as their canonical owner.
The provider's documented import IDs use `repository:file-path:branch`,
with an empty branch for the default branch. No local OpenTofu, SOPS,
state, import, plan, or apply operations were run.
## Impact and rollout
Producer: `tfroot-github` owns both generated files and their resource
state. Consumer: `tfroot-twilio` now contains the exact seeded files on
`main` at
[`315acbf8`](makeitworkcloud/tfroot-twilio@315acbf).
The previous main apply attempted direct creation before the files
existed and failed on repository protection. This PR imports only
`.github/dependabot.yml` and `.github/workflows/dependabot-notify.yml`
into their existing central resources. Its validated plan neither writes
a file nor changes repository protection, Actions secrets, Twilio
configuration, or any GitOps/runtime system. After a confirmed merge,
verify the environment-gated apply succeeds and records the two imports.
Rollback is a reviewed revert of these import declarations. Do not
manually edit the managed target files.
## Safety and secrets
- [x] Contains no plaintext secrets, decrypted SOPS values, state files,
kubeconfigs, tokens, or private endpoints.
- [x] No local OpenTofu init/plan/apply/destroy/import/state operations
were run or claimed — plans come from pull-request checks.
- [x] Breaking or irreversible effects are described above with rollback
notes.
Repository-side secret scanning is unavailable because GitHub Advanced
Security is not enabled; the diff was manually inspected before
publication.
AI agent materially produced this change; reviewers should confirm the
documented import IDs, exact resource addresses, metadata-only lifecycle
exclusions, and retained central ownership.1 parent e24f8aa commit 3932e5f
2 files changed
Lines changed: 32 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
73 | 83 | | |
74 | 84 | | |
75 | 85 | | |
| |||
106 | 116 | | |
107 | 117 | | |
108 | 118 | | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
109 | 128 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
0 commit comments