Connect GitHub¶
Forge App authorization supplies repository access only when a deployment needs it. Ordinary Git operations use the operator's GitHub authority.
Authorization sequence¶
- The operator prepares local account context.
- The customer commits the repository source.
- A deployment request requires repository access.
- Forge begins its App authorization flow.
- Forge reads the authorized repository and committed source.
The flow does not create a second source-control identity. It does not inject a workflow into the repository.
Derived context¶
Authorization and repository context derive environment, tenant, account, installation, and app identity. The customer cannot select those values through the documented CLI.
What to record¶
Record the repository, commit, deployment request, and authorization outcome without recording credentials. Keep ordinary Git operations attributable to the operator's GitHub authority.
This page documents the authorization boundary, not a hosted installation walkthrough. Read Security and trust for the separation of authorities.