| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Note
This information to move into the CDL User Guides Repo that is maintained by IAS once the GitHub working group has this document in a more final state.
GitHub accounts are strongly tied to individual emails.
The use of shared/administrative accounts in actively discouraged by GitHub through multi-factor authentication policies.
GitHub organization policies should be created with an assumption that multiple individual users will adminster policies. These users should be removed from the GitHub organization when the users separate from CDL.
A GitHub account can be configured with multiple email addresses.
We recommend that you associate your UCOP email address with the GitHub account that you use for your work at CDL.
All CDL Github users are required to enable MFA. These can be configured in your account security settings.
It is recommended to enable (2) two-factor methods. Selecting 2 methods provides a backup method if one method is unavailable. It is not recommended to use SMS as this is an insecure method.
Many Git/GitHub operations can be performed within the GitHub web interface.
For work that you perform on your desktop or on a CDL server, you will likely need to authorize a git client to use your GitHub credentials.
Note
GitHub no longer allows you to use your GitHub password to authorize a git client.
Authorization Options
Host github.com HostName github.com User git IdentityFile ~/.ssh/github_rsa
GitHub offers 3 types of plans
Due to cost, CDL does not have an enterprise plan. Most CDL users have been able to qualify for a free pro account as a Teacher using GitHub for Education benefits.
Github organizations are for teams operating shared code and policies. Each CDL program typically has it's own organization.
If you are the owner of an organization and have qualified for Teacher education benefits, you may upgrade your Organization to a Github Team plan
Within each organization there are teams. A GitHub team is a subgroup inside an organization used to manage repo-level access. A member can belong to many teams. (Example: https://github.com/orgs/CDLUC3/teams)
Note: Team in Github are a different concept than the Github Team billing plan
If your project or work would be useful for all of CDL, use the CDLIB Organization. If it's specific to your program, it's recommended to use your program's Github organization.
You can change it later: If you are unsure, start with Private. You can easily switch it to Public later through the repository's Settings menu under the Danger Zone section. Consequences of Changing Visibility
Secrets and credentials (API keys & tokens, passwords, private keys, connection strings) Sensitive Data (env vars, configuration files with secrets, PII date)
Options
Applications may be authorized only for approved use, with least-privilege access, scoped repository permissions, and periodic review by organization administrators.Use cases examples include CI/CD and backups.
We should be very selecitve about the apps that are approved at an Org level.
This is the primary mechanism that we use to enable AWS Code Build/Pipeline tools to access GitHub events.
Access token creation is configured under Settings/Developer Settings/Personal Access Tokens.
If the creator of an access token is not a GitHub Organization owner, the token must be approved by a GitHub Organization Owner before it can be used.
An organization owner can revoke fine-graned tokens that have been granted organization access rights.
Note
At this time, CDL recommends the use of fine-grained access tokens
Options
CDL uses the Github API for Disaster Recovery to backup repositories to external storage areas.
CDL doesn't utilize these due to costs and alternative options such as Docker.
Use protected default branches with required PR reviews, required passing checks, least-privilege permissions, and mandatory security scanning for all repositories.
Each repository should have at least 1 admin assigned to it to manage access.
Github notifications can be quite noisy. Some teams utilize Slack-Github integration for repositories they watch.
At least 2 members should be assigned as an organizational admin. Create an admin account and assign it as an owner. You can use the + email trick to create a separate account for this. (ex: johndoe+gh-adming@ucop.edu). This user can approve Github app connections, access tokens, manage members, and have access to all repositories in the organization.
Most teams at CDL utilize Github Project Boards to manage agile development. Project Boards are very flexible, supporting many views and configurations to track work across a single or multiple repositories. They are typically set to private since they track internal work. Examples of public Github Project Boards can be found here:
Github CoPilot via personal account Github Pro (Github Education benefit) A free subscription for GitHub Copilot is available to verified teachers with GitHub Education. See Getting free access to Copilot as a student, teacher, or maintainer After you approved for Github Education, you can access copilot for free
Users which already have CoPilot can continue to use it until they reach their usage limit each month. Teams find Github CoPilot beneficial utilizing within the browser, helping to write unit tests, review PRs, and embed within their IDE of choice.
Read the Github Blog for news and updates and subscribe to the Github Newsletter for developer updates.
| Back | FazBrowse Home | New Git URL |