mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-04 23:02:04 +00:00
Fix compliance audit workflow and source standards from handbook
- Add missing permissions (id-token, contents, issues) for OIDC auth and issue creation - Fix direct_prompt → prompt (direct_prompt is not a valid input) - Check out engineering-handbook repo as authoritative standards source instead of hardcoding the checklist in the workflow - Create compliance label on-the-fly if it doesn't exist in target repo
This commit is contained in:
parent
6b40091a2b
commit
4c8c033174
1 changed files with 29 additions and 23 deletions
52
.github/workflows/compliance-audit.yaml
vendored
52
.github/workflows/compliance-audit.yaml
vendored
|
|
@ -5,6 +5,11 @@ on:
|
||||||
- cron: "0 14 * * 1" # Every Monday at 10am ET (14:00 UTC)
|
- cron: "0 14 * * 1" # Every Monday at 10am ET (14:00 UTC)
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
id-token: write
|
||||||
|
contents: read
|
||||||
|
issues: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
get-repos:
|
get-repos:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
@ -49,7 +54,7 @@ jobs:
|
||||||
app-id: ${{ secrets.CLAUDE_CI_APP_ID }}
|
app-id: ${{ secrets.CLAUDE_CI_APP_ID }}
|
||||||
private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }}
|
private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }}
|
||||||
owner: Sea-Haven-Industries
|
owner: Sea-Haven-Industries
|
||||||
repositories: ${{ matrix.repo }}
|
repositories: ${{ matrix.repo }},engineering-handbook
|
||||||
|
|
||||||
- name: Checkout repo
|
- name: Checkout repo
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
@ -57,41 +62,42 @@ jobs:
|
||||||
repository: Sea-Haven-Industries/${{ matrix.repo }}
|
repository: Sea-Haven-Industries/${{ matrix.repo }}
|
||||||
token: ${{ steps.app-token.outputs.token }}
|
token: ${{ steps.app-token.outputs.token }}
|
||||||
|
|
||||||
|
- name: Checkout engineering handbook
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: Sea-Haven-Industries/engineering-handbook
|
||||||
|
token: ${{ steps.app-token.outputs.token }}
|
||||||
|
path: .engineering-handbook
|
||||||
|
|
||||||
- name: Run compliance audit
|
- name: Run compliance audit
|
||||||
uses: anthropics/claude-code-action@v1
|
uses: anthropics/claude-code-action@v1
|
||||||
with:
|
with:
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
direct_prompt: |
|
prompt: |
|
||||||
Audit this repository for Sea Haven Industries compliance. Check each item and report pass/fail:
|
Audit this repository for Sea Haven Industries compliance.
|
||||||
|
|
||||||
**Naming:**
|
The engineering handbook in `.engineering-handbook/` is the authoritative source for all conventions. Read every markdown file in that directory to understand the full set of standards, then audit this repo against them.
|
||||||
- All resource names in IaC templates use kebab-case (no snake_case or PascalCase)
|
|
||||||
- Stack name matches repo name
|
|
||||||
|
|
||||||
**Secrets:**
|
Focus on these categories:
|
||||||
- No secrets in Lambda environment variables
|
- **Naming:** kebab-case for all resource names in IaC templates, stack name matches repo name
|
||||||
- No secrets in SSM Parameter Store (should be in Secrets Manager)
|
- **Secrets:** no secrets in Lambda env vars or SSM, secrets belong in Secrets Manager with `stack-name/secret-name` naming
|
||||||
- No hardcoded API keys, tokens, or credentials in source code
|
- **Lambda defaults:** Python 3.12+ or Node 22.x, arm64, explicit 60-day log retention in IaC
|
||||||
- Secret names follow `stack-name/secret-name` convention
|
- **CI/CD:** pipeline exists with CI on PR and CD on push to main, using reusable workflows from `.github` repo
|
||||||
|
- **Git/GitHub:** branch protection on main, PR-based workflow, repo has a description
|
||||||
|
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
|
||||||
|
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
|
||||||
|
|
||||||
**Lambda defaults (if applicable):**
|
Output a concise markdown report with pass/fail per item. Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
|
||||||
- Runtime is Python 3.12+ or Node 22.x
|
|
||||||
- Architecture is arm64
|
|
||||||
- Log retention is explicitly set to 60 days in the IaC template
|
|
||||||
|
|
||||||
**Project hygiene:**
|
|
||||||
- README exists and describes the project architecture
|
|
||||||
- .gitignore exists and covers .env, .aws-sam/, __pycache__
|
|
||||||
- samconfig.toml is gitignored (samconfig.toml.example committed if SAM project)
|
|
||||||
- CloudFormation outputs include function ARNs and URLs
|
|
||||||
|
|
||||||
Output a concise markdown report. Only flag actual violations — don't report items that don't apply (e.g., skip Lambda checks if no Lambdas exist).
|
|
||||||
|
|
||||||
- name: Create issue if violations found
|
- name: Create issue if violations found
|
||||||
if: failure()
|
if: failure()
|
||||||
env:
|
env:
|
||||||
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||||
run: |
|
run: |
|
||||||
|
gh label create compliance \
|
||||||
|
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||||
|
--description "Weekly compliance audit" \
|
||||||
|
--color "D93F0B" 2>/dev/null || true
|
||||||
existing=$(gh issue list \
|
existing=$(gh issue list \
|
||||||
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
|
||||||
--label "compliance" \
|
--label "compliance" \
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue