mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 08:13:12 +00:00
INFRA-58 INFRA-59: org starter workflows + issue templates (#43)
* INFRA-59: add org issue templates (bug, feature, infra-change) + config Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md, infra-change.md (change-control: impact, rollback plan, affected stacks), and config.yml disabling blank issues + routing ops to INFRA Jira. * INFRA-58: add org starter workflows wrapping reusable workflows Adds workflow-templates/ with starters + .properties.json for: ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler, triage. CI/CD starters call the org reusable workflows in .github/.github/workflows/ at @main with their required inputs/secrets.
This commit is contained in:
parent
23584a53c8
commit
7f84f9cfde
18 changed files with 233 additions and 0 deletions
27
.github/ISSUE_TEMPLATE/bug_report.md
vendored
Normal file
27
.github/ISSUE_TEMPLATE/bug_report.md
vendored
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
---
|
||||||
|
name: Bug report
|
||||||
|
about: Report a defect in a Sea Haven service
|
||||||
|
title: "[Bug] "
|
||||||
|
labels: [bug, needs-triage]
|
||||||
|
assignees: amoussa1229
|
||||||
|
---
|
||||||
|
|
||||||
|
## What's wrong
|
||||||
|
<!-- Clear description of the bug. -->
|
||||||
|
|
||||||
|
## Expected behavior
|
||||||
|
<!-- What should happen instead. -->
|
||||||
|
|
||||||
|
## Steps to reproduce
|
||||||
|
1.
|
||||||
|
2.
|
||||||
|
3.
|
||||||
|
|
||||||
|
## Environment / blast radius
|
||||||
|
- Repo / service:
|
||||||
|
- CFN stack affected:
|
||||||
|
- Lambda(s) affected:
|
||||||
|
- Region: us-east-1 (account 328440206208)
|
||||||
|
|
||||||
|
## Logs / evidence
|
||||||
|
<!-- CloudWatch log group + timestamp, request IDs, screenshots. -->
|
||||||
5
.github/ISSUE_TEMPLATE/config.yml
vendored
Normal file
5
.github/ISSUE_TEMPLATE/config.yml
vendored
Normal file
|
|
@ -0,0 +1,5 @@
|
||||||
|
blank_issues_enabled: false
|
||||||
|
contact_links:
|
||||||
|
- name: Internal IT support
|
||||||
|
url: https://seahaven.atlassian.net/jira/software/projects/INFRA
|
||||||
|
about: For operational issues, file an INFRA Jira ticket instead.
|
||||||
21
.github/ISSUE_TEMPLATE/feature_request.md
vendored
Normal file
21
.github/ISSUE_TEMPLATE/feature_request.md
vendored
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
---
|
||||||
|
name: Feature request
|
||||||
|
about: Propose new functionality for a Sea Haven service
|
||||||
|
title: "[Feature] "
|
||||||
|
labels: [enhancement, needs-triage]
|
||||||
|
assignees: amoussa1229
|
||||||
|
---
|
||||||
|
|
||||||
|
## Problem / motivation
|
||||||
|
<!-- What operational pain or gap does this address? -->
|
||||||
|
|
||||||
|
## Proposed solution
|
||||||
|
<!-- What you want to build. -->
|
||||||
|
|
||||||
|
## AWS / integration impact
|
||||||
|
- New or changed AWS resources (Lambda, DynamoDB, S3, API Gateway):
|
||||||
|
- Slack app(s) involved:
|
||||||
|
- Confluence Architecture Map update needed: yes / no
|
||||||
|
|
||||||
|
## Alternatives considered
|
||||||
|
<!-- Other approaches and why they were rejected. -->
|
||||||
26
.github/ISSUE_TEMPLATE/infra-change.md
vendored
Normal file
26
.github/ISSUE_TEMPLATE/infra-change.md
vendored
Normal file
|
|
@ -0,0 +1,26 @@
|
||||||
|
---
|
||||||
|
name: Infrastructure change
|
||||||
|
about: Track a change to AWS infrastructure or integrations (change control)
|
||||||
|
title: "[Infra] "
|
||||||
|
labels: [infra, needs-triage]
|
||||||
|
assignees: amoussa1229
|
||||||
|
---
|
||||||
|
|
||||||
|
## Change summary
|
||||||
|
<!-- What is changing and why. -->
|
||||||
|
|
||||||
|
## Impact assessment
|
||||||
|
- **CFN stack affected:**
|
||||||
|
- **Lambda(s) affected (handler signature change? Y/N):**
|
||||||
|
- **DynamoDB table(s) affected (PITR verified? Y/N):**
|
||||||
|
- **S3 bucket(s) / SES rules affected:**
|
||||||
|
- **Slack app affected:**
|
||||||
|
- **IAM role / policy changes (requires cross-review? Y/N):**
|
||||||
|
|
||||||
|
## Rollback plan
|
||||||
|
<!-- Exact steps to revert: prior stack version, DeletionPolicy considerations, data restore. -->
|
||||||
|
|
||||||
|
## Documentation
|
||||||
|
- [ ] Confluence Architecture Map (id 1540098) update queued
|
||||||
|
- [ ] README updated in same PR
|
||||||
|
- [ ] Project memory entry queued
|
||||||
7
workflow-templates/cdk-deploy.properties.json
Normal file
7
workflow-templates/cdk-deploy.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — Deploy (CDK)",
|
||||||
|
"description": "Deploys a CDK stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-cdk workflow.",
|
||||||
|
"iconName": "octicon-rocket",
|
||||||
|
"categories": ["Deployment", "TypeScript", "Python"],
|
||||||
|
"filePatterns": ["cdk\\.json$"]
|
||||||
|
}
|
||||||
10
workflow-templates/cdk-deploy.yml
Normal file
10
workflow-templates/cdk-deploy.yml
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
name: Deploy (CDK)
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||||
|
secrets:
|
||||||
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||||
7
workflow-templates/ci-node.properties.json
Normal file
7
workflow-templates/ci-node.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — CI (Node / TypeScript / CDK)",
|
||||||
|
"description": "Runs npm ci, tsc --noEmit, optional ESLint/Jest, and cdk synth via the org reusable workflow.",
|
||||||
|
"iconName": "octicon-checklist",
|
||||||
|
"categories": ["TypeScript", "JavaScript", "Continuous integration"],
|
||||||
|
"filePatterns": ["package\\.json$", "tsconfig\\.json$", "cdk\\.json$"]
|
||||||
|
}
|
||||||
8
workflow-templates/ci-node.yml
Normal file
8
workflow-templates/ci-node.yml
Normal file
|
|
@ -0,0 +1,8 @@
|
||||||
|
name: CI (Node / TypeScript)
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
ci:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||||
7
workflow-templates/ci-python.properties.json
Normal file
7
workflow-templates/ci-python.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — CI (Python / SAM)",
|
||||||
|
"description": "Runs ruff check, ruff format --check, pytest, and sam validate --lint via the org reusable workflow.",
|
||||||
|
"iconName": "octicon-checklist",
|
||||||
|
"categories": ["Python", "Continuous integration"],
|
||||||
|
"filePatterns": ["requirements.*\\.txt$", "template\\.ya?ml$", "pyproject\\.toml$"]
|
||||||
|
}
|
||||||
10
workflow-templates/ci-python.yml
Normal file
10
workflow-templates/ci-python.yml
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
name: CI (Python / SAM)
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
ci:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
|
||||||
|
with:
|
||||||
|
run-tests: true
|
||||||
7
workflow-templates/dependency-review.properties.json
Normal file
7
workflow-templates/dependency-review.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — Dependency Review",
|
||||||
|
"description": "Scans PRs for vulnerable or newly-introduced dependencies, failing on high severity. Requires Dependency Graph (GHAS on private repos).",
|
||||||
|
"iconName": "octicon-shield-check",
|
||||||
|
"categories": ["Security", "Dependency management"],
|
||||||
|
"filePatterns": ["package\\.json$", "requirements.*\\.txt$", "pyproject\\.toml$"]
|
||||||
|
}
|
||||||
20
workflow-templates/dependency-review.yml
Normal file
20
workflow-templates/dependency-review.yml
Normal file
|
|
@ -0,0 +1,20 @@
|
||||||
|
name: Dependency Review
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-review:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
- name: Dependency Review
|
||||||
|
uses: actions/dependency-review-action@v4
|
||||||
|
with:
|
||||||
|
fail-on-severity: high
|
||||||
|
comment-summary-in-pr: on-failure
|
||||||
7
workflow-templates/labeler.properties.json
Normal file
7
workflow-templates/labeler.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — PR Labeler",
|
||||||
|
"description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.",
|
||||||
|
"iconName": "octicon-tag",
|
||||||
|
"categories": ["Automation", "Pull requests"],
|
||||||
|
"filePatterns": [".github/labeler\\.ya?ml$"]
|
||||||
|
}
|
||||||
20
workflow-templates/labeler.yml
Normal file
20
workflow-templates/labeler.yml
Normal file
|
|
@ -0,0 +1,20 @@
|
||||||
|
name: Labeler
|
||||||
|
on: [pull_request_target]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
label:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
# Requires .github/labeler.yml in this repo, e.g.:
|
||||||
|
# infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ]
|
||||||
|
# lambda: [ 'lambdas/**', 'src/**', 'functions/**' ]
|
||||||
|
# ci: [ '.github/workflows/**' ]
|
||||||
|
# docs: [ '**/*.md' ]
|
||||||
|
- uses: actions/labeler@v5
|
||||||
|
with:
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
sync-labels: true
|
||||||
7
workflow-templates/sam-deploy.properties.json
Normal file
7
workflow-templates/sam-deploy.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — Deploy (SAM)",
|
||||||
|
"description": "Deploys a SAM stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-sam workflow. Set stack-name and cfn-role-arn before enabling.",
|
||||||
|
"iconName": "octicon-rocket",
|
||||||
|
"categories": ["Deployment", "Python"],
|
||||||
|
"filePatterns": ["template\\.ya?ml$", "samconfig\\.toml$"]
|
||||||
|
}
|
||||||
15
workflow-templates/sam-deploy.yml
Normal file
15
workflow-templates/sam-deploy.yml
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
name: Deploy (SAM)
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
|
||||||
|
with:
|
||||||
|
# Required: the CloudFormation stack name (kebab-case, matches repo name).
|
||||||
|
stack-name: $default-branch
|
||||||
|
# Required: the CloudFormation execution role ARN for this stack.
|
||||||
|
cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role
|
||||||
|
secrets:
|
||||||
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||||
7
workflow-templates/triage.properties.json
Normal file
7
workflow-templates/triage.properties.json
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{
|
||||||
|
"name": "Sea Haven — Issue Triage",
|
||||||
|
"description": "Labels newly opened/reopened issues with needs-triage for weekly review.",
|
||||||
|
"iconName": "octicon-inbox",
|
||||||
|
"categories": ["Automation", "Issues"],
|
||||||
|
"filePatterns": []
|
||||||
|
}
|
||||||
22
workflow-templates/triage.yml
Normal file
22
workflow-templates/triage.yml
Normal file
|
|
@ -0,0 +1,22 @@
|
||||||
|
name: Triage
|
||||||
|
on:
|
||||||
|
issues:
|
||||||
|
types: [opened, reopened]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
triage:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Add needs-triage label
|
||||||
|
uses: actions/github-script@v7
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
await github.rest.issues.addLabels({
|
||||||
|
owner: context.repo.owner,
|
||||||
|
repo: context.repo.repo,
|
||||||
|
issue_number: context.issue.number,
|
||||||
|
labels: ['needs-triage']
|
||||||
|
});
|
||||||
Loading…
Add table
Reference in a new issue