INFRA-58: add org starter workflows wrapping reusable workflows

Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
This commit is contained in:
Adam Moussa 2026-06-05 16:43:58 -04:00
parent fd148d27dc
commit 576cee5a1d
14 changed files with 154 additions and 0 deletions

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Deploy (CDK)",
"description": "Deploys a CDK stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-cdk workflow.",
"iconName": "octicon-rocket",
"categories": ["Deployment", "TypeScript", "Python"],
"filePatterns": ["cdk\\.json$"]
}

View file

@ -0,0 +1,10 @@
name: Deploy (CDK)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Node / TypeScript / CDK)",
"description": "Runs npm ci, tsc --noEmit, optional ESLint/Jest, and cdk synth via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["TypeScript", "JavaScript", "Continuous integration"],
"filePatterns": ["package\\.json$", "tsconfig\\.json$", "cdk\\.json$"]
}

View file

@ -0,0 +1,8 @@
name: CI (Node / TypeScript)
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Python / SAM)",
"description": "Runs ruff check, ruff format --check, pytest, and sam validate --lint via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["Python", "Continuous integration"],
"filePatterns": ["requirements.*\\.txt$", "template\\.ya?ml$", "pyproject\\.toml$"]
}

View file

@ -0,0 +1,10 @@
name: CI (Python / SAM)
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
with:
run-tests: true

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Dependency Review",
"description": "Scans PRs for vulnerable or newly-introduced dependencies, failing on high severity. Requires Dependency Graph (GHAS on private repos).",
"iconName": "octicon-shield-check",
"categories": ["Security", "Dependency management"],
"filePatterns": ["package\\.json$", "requirements.*\\.txt$", "pyproject\\.toml$"]
}

View file

@ -0,0 +1,20 @@
name: Dependency Review
on:
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
fail-on-severity: high
comment-summary-in-pr: on-failure

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — PR Labeler",
"description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.",
"iconName": "octicon-tag",
"categories": ["Automation", "Pull requests"],
"filePatterns": [".github/labeler\\.ya?ml$"]
}

View file

@ -0,0 +1,20 @@
name: Labeler
on: [pull_request_target]
permissions:
contents: read
pull-requests: write
jobs:
label:
runs-on: ubuntu-latest
steps:
# Requires .github/labeler.yml in this repo, e.g.:
# infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ]
# lambda: [ 'lambdas/**', 'src/**', 'functions/**' ]
# ci: [ '.github/workflows/**' ]
# docs: [ '**/*.md' ]
- uses: actions/labeler@v5
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
sync-labels: true

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Deploy (SAM)",
"description": "Deploys a SAM stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-sam workflow. Set stack-name and cfn-role-arn before enabling.",
"iconName": "octicon-rocket",
"categories": ["Deployment", "Python"],
"filePatterns": ["template\\.ya?ml$", "samconfig\\.toml$"]
}

View file

@ -0,0 +1,15 @@
name: Deploy (SAM)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
with:
# Required: the CloudFormation stack name (kebab-case, matches repo name).
stack-name: $default-branch
# Required: the CloudFormation execution role ARN for this stack.
cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Issue Triage",
"description": "Labels newly opened/reopened issues with needs-triage for weekly review.",
"iconName": "octicon-inbox",
"categories": ["Automation", "Issues"],
"filePatterns": []
}

View file

@ -0,0 +1,22 @@
name: Triage
on:
issues:
types: [opened, reopened]
permissions:
issues: write
jobs:
triage:
runs-on: ubuntu-latest
steps:
- name: Add needs-triage label
uses: actions/github-script@v7
with:
script: |
await github.rest.issues.addLabels({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
labels: ['needs-triage']
});