feat: delegate path ownership to domain teams without Maintainer
What does this MR do?
Adds @gitlab-org/orbit/team as a code owner for the Orbit paths, and documents the access model that makes path delegation work without handing out the Maintainer role.
CODEOWNERS
/internal/commands/orbit/and/docs/source/orbit/now list@gitlab-org/orbit/teamalongside the maintainers (and@gl-docsteamon the docs line), following thegovernand dependency firewall pattern.
Documentation
docs/path_ownership.mddescribes the three separate controls: CODEOWNERS grants approval per path, the protected branch Allowed to merge list grants the merge button branch-wide, and the project role grants administration. Only the last needs Maintainer..claude/skills/delegate-path-ownership/SKILL.mdturns the runbook into a skill, so a future delegation is "here is a group and a path" rather than a research exercise.- Linked from
docs/maintainer.md.
Access changes already applied
These took effect immediately and are not part of the diff.
Merge access on main. Every individual and group currently in CODEOWNERS was added to Allowed to merge: the dependency firewall reviewers, the govern reviewers, and @gl-docsteam. They previously needed the Maintainer role to press merge.
Direct Maintainer cleanup: 23 to 3. With merge access granted directly, the direct Maintainer grants were redundant. Access is now carried by group membership:
- 4 maintainers (
jay_mccure,ahmed.hemdan,timofurrer,viktomas) keep Maintainer through thegitlab-cli-maintainersgroup share, so nothing changed for them in practice. - 10 technical writers moved to Developer through the
gl-docsteamshare, which also holds the new merge access entry. - 3 dependency firewall reviewers moved to Developer, covered by CODEOWNERS and their individual merge access entries.
zhaochen_limoved to Developer, inherited fromgitlab-org.SamJoanwas removed. It is a second account for@sroque-worcel, which is the account in CODEOWNERS and holds Developer plus its own merge access entry.
Verified afterwards: everyone still holds at least Developer, apart from the retired second account.
The only remaining direct Maintainers are @phikai and the two service accounts, which were left alone.
Outstanding
gitlab-org/orbit/team still needs to be invited to this project at Developer before its CODEOWNERS entry takes effect. Inviting a group requires the Maintainer or Owner role in that group. Any of @stanhu, @jameslopez, or @dmishunov can run:
glab api --method POST "projects/gitlab-org%2Fcli/share" -f group_id=129386042 -f group_access=30