feat: delegate path ownership to domain teams without Maintainer

What does this MR do?

Adds @gitlab-org/orbit/team as a code owner for the Orbit paths, and documents the access model that makes path delegation work without handing out the Maintainer role.

CODEOWNERS

  • /internal/commands/orbit/ and /docs/source/orbit/ now list @gitlab-org/orbit/team alongside the maintainers (and @gl-docsteam on the docs line), following the govern and dependency firewall pattern.

Documentation

  • docs/path_ownership.md describes the three separate controls: CODEOWNERS grants approval per path, the protected branch Allowed to merge list grants the merge button branch-wide, and the project role grants administration. Only the last needs Maintainer.
  • .claude/skills/delegate-path-ownership/SKILL.md turns the runbook into a skill, so a future delegation is "here is a group and a path" rather than a research exercise.
  • Linked from docs/maintainer.md.

Access changes already applied

These took effect immediately and are not part of the diff.

Merge access on main. Every individual and group currently in CODEOWNERS was added to Allowed to merge: the dependency firewall reviewers, the govern reviewers, and @gl-docsteam. They previously needed the Maintainer role to press merge.

Direct Maintainer cleanup: 23 to 3. With merge access granted directly, the direct Maintainer grants were redundant. Access is now carried by group membership:

  • 4 maintainers (jay_mccure, ahmed.hemdan, timofurrer, viktomas) keep Maintainer through the gitlab-cli-maintainers group share, so nothing changed for them in practice.
  • 10 technical writers moved to Developer through the gl-docsteam share, which also holds the new merge access entry.
  • 3 dependency firewall reviewers moved to Developer, covered by CODEOWNERS and their individual merge access entries.
  • zhaochen_li moved to Developer, inherited from gitlab-org.
  • SamJoan was removed. It is a second account for @sroque-worcel, which is the account in CODEOWNERS and holds Developer plus its own merge access entry.

Verified afterwards: everyone still holds at least Developer, apart from the retired second account.

The only remaining direct Maintainers are @phikai and the two service accounts, which were left alone.

Outstanding

gitlab-org/orbit/team still needs to be invited to this project at Developer before its CODEOWNERS entry takes effect. Inviting a group requires the Maintainer or Owner role in that group. Any of @stanhu, @jameslopez, or @dmishunov can run:

glab api --method POST "projects/gitlab-org%2Fcli/share" -f group_id=129386042 -f group_access=30

🤖 Generated with Claude Code

Edited by Kai Armstrong

Merge request reports

Loading
Loading