SNFR20 - GitHub Teams Only
ID: SNFR20 - Category: Contribution/Support - GitHub Teams Only
All GitHub repositories that AVM modules are published from and hosted within MUST only assign GitHub repository permissions to GitHub teams.
Module ownership MUST be recorded separately from access permissions. Maintain owners in the root metadata.json through the metadata review process. Owner access is managed through the access package described below.
There MUST NOT be any GitHub repository permissions assigned to individual users.
Info
Non-FTE / external contributors (subject matter experts that aren’t Microsoft employees) can’t be members of the teams described in this chapter, hence, they won’t gain any extra permissions on AVM repositories, therefore, they need to work in forks.
Bicep
Note
Access management for Bicep module owners is governed centrally through Microsoft Entra. Per-module GitHub teams and parent-team assignments are no longer required.
All Bicep module owners, including primary and secondary owners, MUST request and obtain approval through the Azure Verified Modules (AVM) Module Contributors access package.
Your GitHub account MUST be linked to your corporate identity and be a member of the Azure organization.
Once approved, access is granted through the azure-verified-modules-module-contributors Entra group and the corresponding @Azure/azure-verified-modules-module-contributors GitHub team. This shared access does not replace individual module ownership and review responsibilities. Adding a handle to metadata does not grant this access.
Bicep module owners MUST continue to work in forks of the BRM repository.
CODEOWNERS file
The BRM CODEOWNERS file retains the repository-wide @Azure/azure-verified-modules-tooling-contributors default and its *avm.core.team.tests.ps1 and *.e2eignore overrides. Its /avm/ entry intentionally has no owners, and it has no per-module entries. Change module ownership in the root metadata.json, not by adding CODEOWNERS entries.
The last rule in CODEOWNERS assigns metadata.json changes to @Azure/azure-verified-modules-engineering-owners and @Azure/azure-verified-modules-module-owners. An eligible member of either team can approve a metadata change; both teams are not required. This special rule still applies to module metadata despite the ownerless /avm/ entry.
The Bicep reviewer-routing workflow uses each root module’s owners array to request reviewers for code changes; children inherit those owners. When a module has no owners, it requests @Azure/azure-verified-modules-module-owners and applies an orphaned-module triage label. These are notifications, not code-owner approvals: ordinary Bicep module code changes may be approved and merged by any eligible repository team member under repository rules. Authors cannot approve their own changes. Being listed in metadata does not grant review permission.
For Bicep and Terraform, both metadata code-owner teams must be visible and have repository write access. Access administration and environment approvals remain separate responsibilities.
Tip
For the full onboarding process and ownership handover steps, see the Bicep Owner Contribution Flow.
Terraform
Note
Access management for Terraform repositories is governed centrally through Microsoft Entra. Module owner access is granted via an Entra access package — it is no longer managed through a per-module GitHub team or the legacy Core Identity entitlement.
All module owners MUST request access via the Azure Verified Modules (AVM) Module Contributors Entra access package:
Once approved, you are added to the azure-verified-modules-module-contributors Entra group, which is the source of truth for who is authorized to own and approve changes on AVM Terraform module repositories. Day-to-day repository access is then granted through this group together with just-in-time (JIT) elevation.
Tip
For the full onboarding process, see the Terraform Prerequisites and Repository Setup pages.