Skip to content

Latest commit

 

History

History
97 lines (69 loc) · 5.44 KB

File metadata and controls

97 lines (69 loc) · 5.44 KB

Zava Workshop Kit

Deploy the Zava Agentic SDLC Workshop into your own GitHub org in 15 minutes.

This kit is the one-stop entry point for org administrators (or curious individuals) who want to stand up the Zava agentic SDLC workshop in their own GitHub org — self-contained, no dependency on any external demo org.

Scope: assumes GitHub (or GitHub Enterprise Cloud) + a GitHub Copilot Business/Enterprise plan in the consumer org. The bootstrap forks a deliberately compromised poisoned-tracing-skill repo as a supply-chain demo fixture — keep workshop deployments in a non-production org. This is an experiment / training kit, not a regulated-production runbook.

What you get

After running the bootstrap, your org owns four working repos:

Repo Role
zava-agent-config Marketplace of 6 reusable Agent Skills + APM kits (secure-baseline, ideate-kit, code-kit, review-kit, release-kit, operate-kit)
zava-storefront A demo Node.js app pre-wired with PR Review Panel + Triage Panel gh aw workflows that consume the marketplace
zava-skills-workshop-template Trainee starter — fork via "Use this template" to author your first Agent Skill
poisoned-tracing-skill A deliberately compromised skill — used in the supply chain demo to show apm install rejecting hidden-Unicode payloads

Plus org-level configuration: 2 secrets, 2 rulesets, 1 apm-policy.yml.

Choose your deployment path

┌───────────────────────────────────────────────────────────────────┐
│ Where are you deploying the workshop?                             │
├───────────────────────────────────────────────────────────────────┤
│ A. Public github.com org (free / Team / Enterprise without EMU)   │
│    → bin/bootstrap.sh + bin/teardown.sh                           │
│    → see Quickstart below                                         │
│                                                                   │
│ B. GitHub Enterprise Cloud with EMU                               │
│    (Enterprise Managed Users — identity-isolated, no public repos)│
│    → bin/bootstrap-emu.sh + bin/teardown-emu.sh                   │
│    → requires bridge engineer with TWO PATs (source + EMU)        │
│    → see docs/emu-setup.md                                        │
└───────────────────────────────────────────────────────────────────┘

Not sure? If your enterprise admin minted your account (handle has a _company suffix), you're EMU — use path B. If you can fork DevExpGbb/zava-agent-config to your org from the GitHub UI, you're not EMU — use path A.

Quickstart — Path A (public github.com org)

# 1. Clone this kit
gh repo clone DevExpGbb/zava-workshop-kit && cd zava-workshop-kit

# 2. Verify your org is ready
./bin/preflight.sh --org=YOUR_ORG

# 3. Deploy the bundle
./bin/bootstrap.sh --org=YOUR_ORG

# 4. Confirm everything works end-to-end
./bin/smoke.sh --org=YOUR_ORG

If smoke.sh exits green, your workshop is live. Hand the trainees zava-skills-workshop-template and tell them to click "Use this template".

Quickstart — Path B (EMU enterprise)

See docs/emu-setup.md for the full bridge-engineer guide. Short version:

export GH_TOKEN_SOURCE=ghp_personal_xxx     # personal github.com PAT (read DevExpGbb)
export GH_TOKEN_TARGET=ghp_emu_xxx           # EMU PAT (admin on target org)

./bin/bootstrap-emu.sh --target-org=YOUR_EMU_ORG --dry-run     # preview
./bin/bootstrap-emu.sh --target-org=YOUR_EMU_ORG               # apply
GH_TOKEN=$GH_TOKEN_TARGET ./bin/smoke.sh --org=YOUR_EMU_ORG    # verify

Read next

Teardown

./bin/teardown.sh --org=YOUR_ORG    # removes all 4 repos + secrets + rulesets (idempotent)

Status

This kit is the canonical home of the workshop bundle. The hackathon-white-pig-8 org you may see referenced in older docs was an ephemeral workshop fixture and may be removed.

License

MIT for the kit itself. Each consuming repo carries its own license.