Prerequisites
Before getting started:- Before calling the GitHub API endpoint in the Async HTTP request block, your organization must already be on Copilot Business or Enterprise and have seat management policies configured.
- You must create a secret in Cortex.
- In this example, the secret in Cortex must be named
GITHUB_COPILOT_TOKEN.
- In this example, the secret in Cortex must be named
Step 1: Start creating the Workflow
Follow the steps in the documentation to create a Workflow and configure its basic settings. Note that Cortex has a pre-built template for this Workflow that contains the Async HTTP request block. The example on this page includes an additional Manual approval block that allows you to designate an approving team. Also in this example, the payload of the Async HTTP block includesapprover": "{{actions.manual-approval.outputs.actor}}, which references the output of the Manual approval block. This reference is not included in the pre-built Workflow template.
Step 2: Add blocks to the Workflow
The instructions on this page describe how to create this Workflow in the Cortex UI, but it is also possible to copy the Workflow YAML and add it to your workspace via the Cortex CLI. This allows you to quickly set up the example configuration then iterate on it for your own use case. Expand the tile below to learn more.Workflow YAML instructions
Workflow YAML instructions
To upload the Workflow example YAML into your workspace:
- Save the Workflow example YAML file below:
- Use the Cortex CLI to run this command, using the path to your Workflow YAML file:
cortex workflows create -f <path-to-your-workflow.yaml>
Manual approval
Manual approval
In this block, you select which team has to give approval for the user to access GitHub Copilot.
- Click + in the center of the page. In the block library modal, choose Manual approval.
- In the block configuration side panel, enter a name and unique slug for this block.
- In this example, we use the name
Manual approvaland the slugmanual-approval.
- In this example, we use the name
- Under Teams allowed to approve, select the teams authorized to approve access to GitHub Copilot.
- Save the block.
Async HTTP request
Async HTTP request
This block looks at the initiating user’s identity mapping in Cortex for GitHub, then calls the GitHub API to grant access to Copilot for that user.
- Click + in the center of the page. In the block library modal, choose Async HTTP request.
- In the block configuration side panel, enter a name and unique slug for this block.
- In this example, we use the name
Grant access to Copilotand the slugcopilot-access.
- In this example, we use the name
- Configure the block:
- HTTP method:
POST - URL: Enter a URL for the request.
- In this example, we call the GitHub endpoint that adds users to your org’s Copilot subscription:
https://api.github.com/orgs/<your-org>/copilot/billing/selected_users
- In this example, we call the GitHub endpoint that adds users to your org’s Copilot subscription:
- Headers:
Authorization: Bearer {{ context.secrets.GITHUB_COPILOT_TOKEN }}- The token you configure must have permissions to manage Copilot seats.
- In this example, the secret in Cortex must be named
GITHUB_COPILOT_TOKEN.
- Payload:
- HTTP method:
- Save the block.
Step 3: Run the Workflow
When you run the Workflow, the following events happen:- The Workflow pauses to collect a response from a member of one of the teams specified during the Manual approval block.
- After a user gives their approval, the Async HTTP request block runs. It uses the initiator of the Workflow as the GitHub user, then makes a call to the GitHub API to provision access to Copilot for that user.