GitHub
GitHub.com or GitHub Enterprise Server.
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Organization | GitHub org name. |
| Repositories | List of repos, or a team/topic filter. Prefer fine-grained over org-wide. |
| Authentication | GitHub App (preferred) or Personal Access Token (PAT). |
| Access scope | Read-only: contents:read, metadata:read. PR/commit metadata for lineage: pull_requests:read. |
Network considerations
GitHub.com: HTTPS over 443. No VPN needed.
GitHub Enterprise Server (on-prem): Must be reachable from Flume. VPN or public endpoint with IP allowlist.
IP allowlist: If org restricts GitHub App access by IP, add Flume’s egress IPs.
Credential and auth management
Preferred: GitHub App. Installation tokens are short-lived (1 hour), auto-rotated, scoped to specific repos. No human account needed.
Acceptable: Fine-grained PAT. Scoped to specific repos and permissions. 90-day max expiry default. Requires rotation.
Acceptable: Classic PAT. Broader scope, less secure. Last resort.
SAML SSO: If org uses SAML, PATs must be SAML-authorized after creation.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET /user (PAT) or GET /app (App) | 200 with identity |
| Repo access | GET /repos/<org>/<repo> | 200 with repo metadata |
| Contents read | GET /repos/<org>/<repo>/contents/ | Lists root directory |
| Commit history | GET /repos/<org>/<repo>/commits?per_page=1 | Returns latest commit |
| Rate limit | GET /rate_limit | Sufficient remaining quota (5000/hr for App) |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.