github / roadmap

GitHub public roadmap
Creative Commons Attribution 4.0 International
7.88k stars 974 forks source link

Actions: More secure deployments to protected environments #825

Closed github-product-roadmap closed 6 months ago

github-product-roadmap commented 1 year ago

Summary

We are now shipping a few enhancements around Actions environments guarded by "deployment protection rules" to make it easy for admins to secure their deployment rollouts.

Intended Outcome

These enhancements will help admins to have more secure and controlled deployments across Environments

How will it work?

Admins who want to have more controlled deployments can now prevent self-reviews, configure Tag patterns to say, allow only Releases/* Tags to deploy to their Production Environment. And also configure that if a reviewer doesn't approve a deployment beyond 5 days, then the deployment would just fail.

ankneis commented 11 months ago

🚢 Allow deployments only for selected Tag patterns has shipped: https://github.blog/changelog/2023-10-06-actions-secure-deployment-rollouts-to-protected-environments-based-on-select-tag-patterns/

Leaving open to track for other related releases.

ankneis commented 11 months ago

🚢 Prevent self reviews feature has shipped: https://github.blog/changelog/2023-10-16-actions-prevent-self-reviews-for-secure-deployments-across-actions-environments/

Leaving open to track for remaining feature release.

ankneis commented 9 months ago

~This is available for GHES 3.11: https://docs.github.com/en/enterprise-server@3.11/admin/release-notes~

This was an error and the feature will actually ship with GHES 3.12.

ankneis commented 6 months ago

🚢 This has shipped with GHES 3.12: https://docs.github.com/en/enterprise-server@3.12/admin/release-notes