brlin-tw/gitlab2github-push-mirror-utils

★ 0Forks 0ShellGitHub ↗Compare

README

gitlab2github-push-mirror-utils

Utilities for managing GitLab-to-GitHub push mirror configurations.

https://gitlab.com/brlin/gitlab2github-push-mirror-utils
The GitLab CI pipeline status badge of the project's main branch GitHub Actions workflow status badge pre-commit enabled badge REUSE Specification compliance badge

Preparation

  1. Download the product's release archive from the Releases page.
  2. Extract the downloaded archive.

The rotate-gitlab2github-push-mirror-credentials.sh utility

Batch rotate credentials of GitLab push mirroring settings for all repositories in a namespace that is configured to push to GitHub.

Prerequisites

The following prerequisites must be met in order to use this utility:

  • The host running the utility must have Internet access.
  • The host running the utility must have the following software installed and its commands to be available in your command search PATHs:
    • curl
      For interacting with GitLab and GitHub's API.
    • grep
      sed
      For parsing the curl command's output.
    • jq
      For parsing the JSON response of GitLab and GitHub's API.

Usage

  1. Set the environment variables documented in the Environment variables that can change the utility's behaviors section.
  2. Run the rotate-gitlab2github-push-mirror-credentials.sh script.
  3. Provide the prompted values documented in the Prompted variables that can change the utility's behaviors section.

Environment variables that can change the utility's behaviors

The following environment variables can be used to change the utility's behaviors according to your needs:

GITLAB_NAMESPACE

GitLab namespace to replace push mirroring settings, currently namespaces including subgroup is not supported.

Default value: Value of the USER environment variable(e.g. Your username).

GITHUB_NAMESPACE

GitHub namespace to configure push mirroring to.

Default value: Value of the GITLAB_NAMESPACE environment variable.

GITLAB_API_ENDPOINT

The GitLab REST API v4-compatible endpoint to use.

Default value: https://gitlab.com/api/v4

GITHUB_API_ENDPOINT

The GitHub API v2022-11-28-compatible endpoint to use.

Default value: https://api.github.com

PAGINATION_ENTRIES

The number of entries per page to request when pagination is required.

Default value: 100

Prompted variables that can change the utility's behaviors

The following variables can be used to change the utility's behaviors, they are prompted when running the utility due to their sensitive nature:

GITLAB_PAT

The personal access token with access to the GitLab namespace. REQUIRED.

Required fine-grained personal access token resource permissions:

  • User:
    • Groups:
      • Namespace
        • Read: For querying available projects in the namespace.
  • Group and project:
    • Project Features:
      • Remote Mirror:
        • Create: For creating a new repository push mirroring configuration.
        • Delete: For removing the existing repository push mirroring configuration.
        • Read: For checking the existing repository push mirroring configuration.

Default value: (none)

GITHUB_PAT

The personal access token with access to the GitHub namespace. This is used to:

  • Mitigate GitHub rate limiting.
  • Authenticate the user during the GitLab push mirroring process.

REQUIRED.

It should have the following GitHub fine-grained permissions:

  • Repository permissions > Read access to metadata
  • Repository permissions > Read and write access to:
    • Contents: To allow GitLab to push non-GitHub Actions workflow related content to the mirrored repository.
    • Workflows: To allow GitLab to push GitHub Actions workflow related content to the mirrored repository.

Default value: (none)

Logic

The following documents the logic of this utility in operation:

  1. A list of all GitLab projects in a namespace is queried via GitLab's REST API.
  2. For each GitLab project:
    1. Determine the URL of the corresponding GitHub project(repository).
    2. Check whether the GitHub project actually exists.
    3. If the project exists in the specified GitHub namespace, check whether the GitLab project has an repository mirroring configuration against it.
    4. If the repository mirroring configuration does not exist, skipping this project as we aren't sure the GitLab project has all the commits from GitHub yet.
    5. If the repository mirroring configuration exists, remove the configuration.
    6. Create a new repository mirroring configuration with the updated GitHub PAT.

Limitations

The product does not support GitLab subgroups, they will be skipped.

References

The following materials are referenced during the development of this project:

Licensing

Unless otherwise noted(individual file's header/REUSE.toml), this product is licensed under the 3.0 version of the GNU Affero General Public License license, or any of its recent versions you would prefer.

This work complies to the REUSE Specification, refer to the REUSE - Make licensing easy for everyone website for info regarding the licensing of this product.

Contributors

brlin-tw

Issues